PT-2018-10025 · Safervpn+1 · Safervpn+1
Fabius Watson
+1
·
Published
2018-05-02
·
Updated
2019-10-03
·
CVE-2018-10647
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SaferVPN version 4.2.5
Description
The issue concerns a privilege escalation problem in the "SaferVPN.Service" service of SaferVPN for Windows. This service runs "openvpn.exe" using configuration files from the user's %LOCALAPPDATA%SaferVPNOvpnConfig directory. An authenticated attacker can modify these configuration files to specify a dynamic library plugin that runs for every new VPN connection attempt, allowing the execution of code in the context of the SYSTEM user.
Recommendations
For SaferVPN version 4.2.5, consider restricting access to the %LOCALAPPDATA%SaferVPNOvpnConfig directory to prevent modification of OpenVPN configuration files until a patch is available. As a temporary workaround, disabling the "SaferVPN.Service" service may mitigate the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openvpn
Safervpn