CVE-2023-47267

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
19/12/2023
Last modified:
17/12/2025

Description

An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:thegreenbow:thegreenbow_vpn_client:*:*:*:*:enterprise_certified:windows:*:* 6.52.004 (including) 6.52.006 (excluding)
cpe:2.3:a:thegreenbow:thegreenbow_vpn_client:*:*:*:*:standard:windows:*:* 6.87.001 (including) 6.87.108 (excluding)
cpe:2.3:a:thegreenbow:thegreenbow_vpn_client:*:*:*:*:enterprise:windows:*:* 6.87.001 (including) 6.87.109 (excluding)