PT-2018-1297 · Proton+1 · Protonvpn+1

Fabius Watson

+1

·

Published

2018-03-23

·

Updated

2019-10-03

·

CVE-2018-10169

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProtonVPN version 1.3.3
Description The issue is related to insufficient access control in the ProtonVPN service, which establishes a NetNamedPipe endpoint. This allows arbitrary installed applications to connect and call publicly exposed methods, such as the Connect method. The Connect method accepts a class instance argument, providing attacker control over the OpenVPN command line. An attacker can specify a dynamic library plugin to execute code in the context of the SYSTEM user. This could allow a remote attacker to execute arbitrary code with SYSTEM privileges using the OpenVPN command line.
Recommendations For ProtonVPN version 1.3.3, consider disabling the ProtonVPN Service until a patch is available to prevent potential exploitation. Restrict access to the NetNamedPipe endpoint to minimize the risk of arbitrary code execution. Avoid using the dynamic library plugin feature in the OpenVPN command line until the issue is resolved.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00793
CVE-2018-10169

Affected Products

Openvpn
Protonvpn