Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:leap:bitmask_riseup_vpn:0.21.6:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2021-44466 |
Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower privileged users to replace the VPN executable with a malicious one. When a higher privileged user such as an Administrator launches that executable, it is possible for the lower privileged user to escalate to Administrator privileges. Published: December 30, 2021; 5:15:09 PM -0500 |
V3.1: 7.3 HIGH V2.0: 4.6 MEDIUM |