ZeroHour

CVE-2021-31776

CVSS 3.1
7.8 high
EPSS
<1%p24
Published
()
Modified
Description

Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.

Vendors
aviatrix
Products
vpn client
Weakness
CWE-428
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.