PT-2022-17250 · Unknown · Pritunl Client

David Yesland

·

Published

2022-02-20

·

Updated

2022-04-27

·

CVE-2022-25372

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pritunl Client versions 1.2.3019.52 and earlier
Description The issue allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform windows.go. This affects Pritunl Client on Windows.
Recommendations For Pritunl Client version 1.2.3019.52 and earlier, consider updating to a version that fixes the local privilege escalation issue, although the specific fixed version is not provided in the available data. As a temporary workaround, consider restricting access to the vulnerable ACL entry for CREATOR OWNER in platform windows.go until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25372

Affected Products

Pritunl Client