PT-2025-17388 · Unknown · Pritunl Client

Egor Filatov

·

Published

2025-04-01

·

Updated

2025-04-19

·

CVE-2025-43917

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pritunl Client versions prior to 1.3.4220.57
Description The issue allows an administrator with access to /Applications to escalate privileges after uninstalling the product. This is achieved by inserting a new file at the pathname of the removed pritunl-service file, which is then executed by a LaunchDaemon as root. The pritunl-service file is specifically targeted in this exploit.
Recommendations For versions prior to 1.3.4220.57, update to version 1.3.4220.57 or later to resolve the issue. As a temporary workaround, consider restricting access to the /Applications directory to prevent potential exploitation. Additionally, monitor LaunchDaemon executions to detect any suspicious activity.

Fix

LPE

Incorrect Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-08463
CVE-2025-43917

Affected Products

Pritunl Client