PT-2018-10025 · Safervpn+1 · Safervpn+1

Fabius Watson

+1

·

Published

2018-05-02

·

Updated

2019-10-03

·

CVE-2018-10647

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SaferVPN version 4.2.5
Description The issue concerns a privilege escalation problem in the "SaferVPN.Service" service of SaferVPN for Windows. This service runs "openvpn.exe" using configuration files from the user's %LOCALAPPDATA%SaferVPNOvpnConfig directory. An authenticated attacker can modify these configuration files to specify a dynamic library plugin that runs for every new VPN connection attempt, allowing the execution of code in the context of the SYSTEM user.
Recommendations For SaferVPN version 4.2.5, consider restricting access to the %LOCALAPPDATA%SaferVPNOvpnConfig directory to prevent modification of OpenVPN configuration files until a patch is available. As a temporary workaround, disabling the "SaferVPN.Service" service may mitigate the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10647

Affected Products

Openvpn
Safervpn