← Back

CVE-2021-31776

nvd nist
Published: Apr 29, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.

Affected (1)

Products: Aviatrix: Vpn Client
1 product
Vpn Client
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.14.14
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (6)

Source: cve@mitre.org
ProductVendor Advisory
Source: cve@mitre.org
ProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.