PT-2019-12864 · London Trust Media · Private Internet Access (Pia) Vpn Client

Rich Mirch

·

Published

2019-07-11

·

Updated

2019-07-16

·

CVE-2019-12574

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions London Trust Media Private Internet Access (PIA) VPN Client version 1.0
Description A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The issue is related to a DLL injection vulnerability during the software update process, where the updater loads several libraries from a folder that authenticated users have write access to. This allows a low-privileged user to execute arbitrary code as SYSTEM.
Recommendations For London Trust Media Private Internet Access (PIA) VPN Client version 1.0, consider restricting access to the folder where the updater loads libraries to prevent low-privileged users from exploiting the DLL injection vulnerability. As a temporary workaround, consider disabling the software update process until a patch is available.

Exploit

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-12574

Affected Products

Private Internet Access (Pia) Vpn Client