CVE-2021-35523

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
28/06/2021
Last modified:
02/07/2021

Description

Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:securepoint:openvpn-client:*:*:*:*:*:windows:*:* 2.0.15 (including) 2.0.32 (excluding)