Get a Pentest and security assessment of your IT network.

News

Vulnerability Spotlight: CVE-2018-3952 / CVE-2018-4010 – Multi-provider VPN Client Privilege Escalation Vulnerabilities

Cisco Talos has discovered two similar vulnerabilities in the ProtonVPN and NordVPN VPN clients. The vulnerabilities allow attackers to execute code as an administrator on Microsoft Windows operating systems from a standard user. Despite the fix, it is still possible to execute software on the system. The details section later on in this post will explain the first patch, why it was not successful, and how the editors finally fixed the problem. Both clients have the same design: The user interface is executed with the permission of the logged-in user. The goal of the binary is to execute the OpenVPN client binary with the user configuration file.”]

Source: https://blog.talosintelligence.com/2018/09/vulnerability-spotlight-Multi-provider-VPN-Client-Privilege-Escalation.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks