CyberGhost 6 for Windows
Privilege Escalation
CVE ID
Vendor
CyberGhost S.R.L.
Product
CyberGhost 6
Product Version
6.5.0.3180
Vulnerability Details
CyberGhost 6 for Windows suffers from a SYSTEM
privilege escalation vulnerability through the CG6Service
service. This service establishes an NetNamedPipe
endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The ConnectToVpnServer
method accepts a connectionParams
argument that provides attacker control of the OpenVpn command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM
user
Vendor Response
A release is scheduled
Disclosure Timeline
-
Vendor disclosure via email
-
Vendor disclosure via email
-
Vendor notified via Facebook
-
Vendor response: Received
-
Vendor response and followup
-
Vendor response: Something that will be fixed with the next release
-
Vendor notified of the advisory release