PT-2019-12864 · London Trust Media · Private Internet Access (Pia) Vpn Client
Rich Mirch
·
Publicado
2019-07-11
·
Atualizado
2019-07-16
·
CVE-2019-12574
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
London Trust Media Private Internet Access (PIA) VPN Client version 1.0
Description
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The issue is related to a DLL injection vulnerability during the software update process, where the updater loads several libraries from a folder that authenticated users have write access to. This allows a low-privileged user to execute arbitrary code as SYSTEM.
Recommendations
For London Trust Media Private Internet Access (PIA) VPN Client version 1.0, consider restricting access to the folder where the updater loads libraries to prevent low-privileged users from exploiting the DLL injection vulnerability. As a temporary workaround, consider disabling the software update process until a patch is available.
Exploit
Correção
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Private Internet Access (Pia) Vpn Client