PT-2021-11400 · Unknown+1 · Pritunl Client+1

Published

2021-04-30

·

Updated

2021-05-11

·

CVE-2020-27519

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Pritunl Client version 1.2.2550.20
Description: The issue concerns a local privilege escalation in the pritunl-service component. It can be exploited through a malicious OpenVPN config, allowing a local attacker to leverage log and log-append features along with log injection. This enables the creation or appending to privileged script files, resulting in the execution of code as root or SYSTEM.
Recommendations: For Pritunl Client version 1.2.2550.20, consider disabling the pritunl-service component until a patch is available to prevent potential exploitation. Restrict access to the log and log-append features to minimize the risk of log injection. Avoid using malicious OpenVPN configs to prevent the escalation of privileges. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27519

Affected Products

Openvpn
Pritunl Client