PT-2019-12864 · London Trust Media · Private Internet Access (Pia) Vpn Client
Rich Mirch
·
Published
2019-07-11
·
Updated
2019-07-16
·
CVE-2019-12574
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
London Trust Media Private Internet Access (PIA) VPN Client version 1.0
Description
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The issue is related to a DLL injection vulnerability during the software update process, where the updater loads several libraries from a folder that authenticated users have write access to. This allows a low-privileged user to execute arbitrary code as SYSTEM.
Recommendations
For London Trust Media Private Internet Access (PIA) VPN Client version 1.0, consider restricting access to the folder where the updater loads libraries to prevent low-privileged users from exploiting the DLL injection vulnerability. As a temporary workaround, consider disabling the software update process until a patch is available.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Private Internet Access (Pia) Vpn Client