Lucene search

K
attackerkbAttackerKBAKB:78FBC9F2-B057-4F10-A61A-7118987C34A4
HistoryMar 28, 2019 - 12:00 a.m.

CVE-2019-17388

2019-03-2800:00:00
attackerkb.com
11

0.0004 Low

EPSS

Percentile

5.1%

Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.

Recent assessments:

kevthehermit at March 05, 2020 9:34am UTC reported:

VPN clients are commonly found on laptops for remote office workers, This is a local priv esc on all Aviatrix VPN Clients. As it is local it would need either a malicious user or an attacker with User level access looking to escalate.

Due to file permissions on scripts that are executed to start and stop the VPN client, it is trivial to inject arbitrary OS commands that can be used to escalate privs.

<https://immersivelabs.com/2019/12/04/aviatrix-vpn-client-vulnerability/&gt;

Assessed Attacker Value: 4
Assessed Attacker Value: 4Assessed Attacker Value: 5

0.0004 Low

EPSS

Percentile

5.1%

Related for AKB:78FBC9F2-B057-4F10-A61A-7118987C34A4