Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITYSYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under %APPDATA%Securepoint SSL VPN and add a external script file that is executed as privileged user.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Openvpn-client | Securepoint | 2.0.15 (including) | 2.0.32 (excluding) |