CyberGhost 6 for Windows
Privilege Escalation
CVE ID
Vendor
CyberGhost S.R.L.
Product
CyberGhost 6
Product Version
6.5.0.3180
Vulnerability Details
CyberGhost 6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the CG6Service service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The ConnectToVpnServer method accepts a connectionParams argument that provides attacker control of the OpenVpn command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user
Vendor Response
A release is scheduled
Disclosure Timeline
-
Vendor disclosure via email
-
Vendor disclosure via email
-
Vendor notified via Facebook
-
Vendor response: Received
-
Vendor response and followup
-
Vendor response: Something that will be fixed with the next release
-
Vendor notified of the advisory release