PT-2018-9862 · Openvpn+1 · Openvpn+1

Fabius Watson

+1

·

Published

2018-04-26

·

Updated

2019-10-03

·

CVE-2018-10381

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TunnelBear version 3.2.0.6
Description: The issue concerns a privilege escalation through the TunnelBearMaintenance service, which sets up a NetNamedPipe endpoint. This allows any installed application to connect and invoke publicly exposed methods. Specifically, the OpenVPNConnect method is vulnerable as it accepts a server list argument, giving an attacker control over the OpenVPN command line. An attacker can specify a dynamic library plugin to run for every new VPN connection attempt, executing code in the context of the SYSTEM user.
Recommendations: For TunnelBear version 3.2.0.6, consider disabling the TunnelBearMaintenance service as a temporary workaround until a patch is available. Restrict access to the NetNamedPipe endpoint to minimize the risk of exploitation. Avoid using the OpenVPNConnect method in the affected service until the issue is resolved.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10381

Affected Products

Openvpn
Tunnelbear