CVE-2021-35523
28.06.2021, 17:15
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.Enginsight
Vendor | Product | Version |
---|---|---|
securepoint | openvpn-client | 2.0.15 ≤ 𝑥 < 2.0.32 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References