CVE-2022-24141
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/07/2022
Last modified:
14/07/2022
Description
The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing ImpersonateNamedPipeClient().
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:iobit:itop_vpn:3.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



