PT-2019-12864 · London Trust Media · Private Internet Access (Pia) Vpn Client

Rich Mirch

·

Publicado

2019-07-11

·

Atualizado

2019-07-16

·

CVE-2019-12574

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions London Trust Media Private Internet Access (PIA) VPN Client version 1.0
Description A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The issue is related to a DLL injection vulnerability during the software update process, where the updater loads several libraries from a folder that authenticated users have write access to. This allows a low-privileged user to execute arbitrary code as SYSTEM.
Recommendations For London Trust Media Private Internet Access (PIA) VPN Client version 1.0, consider restricting access to the folder where the updater loads libraries to prevent low-privileged users from exploiting the DLL injection vulnerability. As a temporary workaround, consider disabling the software update process until a patch is available.

Exploit

Correção

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12574

Produtos afetados

Private Internet Access (Pia) Vpn Client