← Back

CVE-2014-5455

nvd nist
Published: Aug 25, 2014Modified: May 28, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Exploitability: 1.8 / Impact: 3.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

Affected (2)

1 product
Openvpn
1 product
Privatetunnel
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.1.28.0
Version 2.3.8

Timeline

No history available yet.