PT-2024-4470 · Windscribe · Windscribe

Zeze

·

Published

2024-05-30

·

Updated

2024-08-25

·

CVE-2024-6141

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windscribe (affected versions not specified)
Description The issue is related to a directory traversal vulnerability in the Windscribe Service, which can be exploited by local attackers to escalate privileges on affected installations of Windscribe. This can be achieved by leveraging the lack of proper validation of a user-supplied path prior to using it in file operations, allowing an attacker to execute arbitrary code in the context of SYSTEM. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-04972
CVE-2024-6141
ZDI-24-820

Affected Products

Windscribe