PT-2026-5118 · Node Security · Nordvpn
Chipo
·
Published
2026-01-28
·
Updated
2026-01-28
·
CVE-2020-36992
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nord VPN version 6.31.13.0
Description
Nord VPN version 6.31.13.0 has an unquoted service path vulnerability in its
nordvpn-service. This allows local attackers to execute code with elevated privileges. The vulnerability stems from an unquoted binary path, which attackers can exploit during system startup or reboot to potentially run malicious code with LocalSystem permissions.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider modifying the service path to include quotes to prevent execution of unauthorized code.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nordvpn