PT-2018-9862 · Openvpn+1 · Openvpn+1
Fabius Watson
+1
·
Published
2018-04-26
·
Updated
2019-10-03
·
CVE-2018-10381
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
TunnelBear version 3.2.0.6
Description:
The issue concerns a privilege escalation through the TunnelBearMaintenance service, which sets up a NetNamedPipe endpoint. This allows any installed application to connect and invoke publicly exposed methods. Specifically, the OpenVPNConnect method is vulnerable as it accepts a server list argument, giving an attacker control over the OpenVPN command line. An attacker can specify a dynamic library plugin to run for every new VPN connection attempt, executing code in the context of the SYSTEM user.
Recommendations:
For TunnelBear version 3.2.0.6, consider disabling the TunnelBearMaintenance service as a temporary workaround until a patch is available. Restrict access to the NetNamedPipe endpoint to minimize the risk of exploitation. Avoid using the OpenVPNConnect method in the affected service until the issue is resolved.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openvpn
Tunnelbear