CVE-2021-35523
Securepoint SSL VPN Client 2.0.30 Local Privilege Escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.
Securepoint SSL VPN Client versiones v2 anteriores a 2.0.32, en Windows, presenta un manejo de configuración no seguro que permite una escalada de privilegios local a NT AUTHORITY\SYSTEM. Un usuario local no privilegiado puede modificar la configuración de OpenVPN almacenado en "%APPDATA%\Securepoint SSL VPN" y añadir un archivo de script externo que es ejecutado como usuario privilegiado
Securepoint SSL VPN Client version 2.0.30 suffers from a local privilege escalation vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-06-28 CVE Reserved
- 2021-06-28 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://seclists.org/fulldisclosure/2021/Jun/59 | Mailing List | |
https://github.com/Securepoint/openvpn-client/security/advisories/GHSA-v8p8-4w8f-qh34 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Securepoint Search vendor "Securepoint" | Openvpn-client Search vendor "Securepoint" for product "Openvpn-client" | >= 2.0.15 < 2.0.32 Search vendor "Securepoint" for product "Openvpn-client" and version " >= 2.0.15 < 2.0.32" | windows |
Affected
|