Description
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.pango.co/sec31944/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:04:22.936Z
Reserved: 2020-05-13T00:00:00.000Z
Link: CVE-2020-12828
No data.
Status : Modified
Published: 2020-05-21T17:15:10.227
Modified: 2024-11-21T05:00:21.300
Link: CVE-2020-12828
No data.
OpenCVE Enrichment
No data.
Weaknesses