Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.
References
Link | Resource |
---|---|
https://github.com/pritunl/pritunl-client-electron/commit/e16d47437f8ef62546aa00edb0d64be2a7d2205b | Patch Third Party Advisory |
https://github.com/pritunl/pritunl-client-electron/blob/caa78d626198b6961f3f39eca2acd39064c2df96/CHANGES#L6 | Release Notes Third Party Advisory |
https://rhinosecuritylabs.com/penetration-testing/cve-2022-25372-local-privilege-escalation-in-pritunl-vpn-client/ | Exploit Technical Description Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-02-20 12:15
Updated : 2022-04-27 10:04
NVD link : CVE-2022-25372
Mitre link : CVE-2022-25372
JSON object : View
CWE
CWE-269
Improper Privilege Management
Products Affected
pritunl
- pritunl-client-electron
microsoft
- windows