SaferVPN for Windows
SaferVPN for Windows suffers from a SYSTEM
privilege escalation vulnerability in its SaferVPN.Service
service. The SaferVPN.Service
service executes openvpn.exe
using OpenVPN config files located within the current user’s local application data directory i.e. AppDataLocalSaferVPNOvpnConfig
. An authenticated attacker may modify these configuration files to specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM
user.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /