PT-2020-14927 · Anchorfree · Hotspot Shield Vpn

Published

2020-09-24

·

Updated

2020-10-23

·

CVE-2020-17365

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hotspot Shield VPN client software versions 10.3.0 and earlier
Description The issue is related to improper directory permissions, which may allow an authorized user to potentially enable escalation of privilege via local access. This could allow a local user to corrupt system files by creating a specially crafted symbolic link to a critical file on the system and overwriting it with privileges of the application.
Recommendations For versions 10.3.0 and earlier, update to a version later than 10.3.0 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-17365

Affected Products

Hotspot Shield Vpn