PT-2018-3678 · Aviatrix · Aviatrix Vpn Client

Alex Seymour

·

Published

2018-12-05

·

Updated

2020-08-24

·

CVE-2019-17388

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aviatrix VPN Client versions through 2.2.10
Description The issue is related to weak file permissions applied to the Aviatrix VPN Client installation directory on Windows and Linux. This allows a local attacker to execute arbitrary code by gaining elevated privileges through file modifications. The vulnerability can be exploited to allow an attacker to run arbitrary code.
Recommendations For Aviatrix VPN Client versions through 2.2.10, consider restricting access to the installation directory to prevent file modifications until a patch is available. As a temporary workaround, ensure that the file system permissions are set to prevent unauthorized modifications to the Aviatrix VPN Client installation directory. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03005
CVE-2019-17388

Affected Products

Aviatrix Vpn Client