← Back

Bitmask Riseup Vpn

bitmask_riseup_vpn

Vendor: Leap • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Leap
1Bitmask Riseup Vpn
Nov 21, 2024
Dec 30, 2021
N/A· v4
7.3 HIGH· v3
4.6 MEDIUM· v2
Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails t...Show more
Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower privileged users to replace the VPN executable with a malicious one. When a higher privileged user such as an Administrator launches that executable, it is possible for the lower privileged user to escalate to Administrator privileges.Show less