CyberGhost 6 for Windows

Privilege Escalation

Vendor

CyberGhost S.R.L.

Product

CyberGhost 6

Product Version

6.5.0.3180

Vulnerability Details

CyberGhost 6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the CG6Service service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The ConnectToVpnServer method accepts a connectionParams argument that provides attacker control of the OpenVpn command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user

Vendor Response

A release is scheduled

Disclosure Timeline

  • Vendor disclosure via email

  • Vendor disclosure via email

  • Vendor notified via Facebook

  • Vendor response: Received

  • Vendor response and followup

  • Vendor response: Something that will be fixed with the next release

  • Vendor notified of the advisory release