PT-2026-8316 · Total Vpn+1 · Total Vpn+1
Cyber-Wo0Dy
·
Published
2026-02-16
·
Updated
2026-02-21
·
CVE-2026-2542
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Total VPN version 0.5.29.0
Description
A security issue exists in Total VPN 0.5.29.0 on Windows related to an unquoted search path within the file
C:Program FilesTotal VPNwin-service.exe. This can lead to potential local privilege escalation. The exploitation of this issue is considered difficult and requires high complexity. The vendor was contacted regarding this issue but did not provide a response.Recommendations
Review directory permissions for the affected file.
Monitor the system closely for any suspicious activity.
Fix
LPE
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Total Vpn
Windows