PT-2018-1557 · Protonvpn · Protonvpn Vpn Client

Published

2018-09-07

·

Updated

2023-02-04

·

CVE-2018-4010

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProtonVPN VPN client version 1.5.1
Description A code execution issue exists in the connect functionality of the ProtonVPN VPN client, allowing for privilege escalation. This can be triggered by a specially crafted configuration file, enabling an attacker to execute arbitrary commands with system privileges.
Recommendations For ProtonVPN VPN client version 1.5.1, consider disabling the connect functionality until a patch is available to prevent potential exploitation. Restrict access to configuration files to minimize the risk of a specially crafted file being used to escalate privileges.

Exploit

Fix

OS Command Injection

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2018-01112
CVE-2018-4010

Affected Products

Protonvpn Vpn Client