PT-2019-17980 · Forcepoint · Forcepoint Vpn Client For Windows
Peleg Hadar
·
Published
2019-09-20
·
Updated
2022-04-18
·
CVE-2019-6145
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Forcepoint VPN Client for Windows versions lower than 6.6.1
Description
The issue allows for local privilege escalation to the SYSTEM user due to an unquoted search path vulnerability. By default, only local administrators can write executables to the vulnerable directories.
Recommendations
For Forcepoint VPN Client for Windows versions lower than 6.6.1, update to version 6.6.1 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forcepoint Vpn Client For Windows