PT-2026-8316 · Total Vpn+1 · Total Vpn+1
Cyber-Wo0Dy
·
Publicado
2026-02-16
·
Atualizado
2026-02-21
·
CVE-2026-2542
CVSS v3.1
7.0
Alta
| Vetor | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Total VPN version 0.5.29.0
Description
A security issue exists in Total VPN 0.5.29.0 on Windows related to an unquoted search path within the file
C:Program FilesTotal VPNwin-service.exe. This can lead to potential local privilege escalation. The exploitation of this issue is considered difficult and requires high complexity. The vendor was contacted regarding this issue but did not provide a response.Recommendations
Review directory permissions for the affected file.
Monitor the system closely for any suspicious activity.
Correção
LPE
Untrusted Search Path
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Total Vpn
Windows