CVE Vulnerabilities

CVE-2021-35523

Improper Privilege Management

Published: Jun 28, 2021 | Modified: Jul 02, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITYSYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under %APPDATA%Securepoint SSL VPN and add a external script file that is executed as privileged user.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Openvpn-client Securepoint 2.0.15 (including) 2.0.32 (excluding)

Potential Mitigations

References