First published: Thu Dec 05 2019(Updated: )
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Aviatrix VPN Client | <=2.2.10 | |
FreeBSD Kernel | ||
Linux Kernel | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-17388.
The severity of CVE-2019-17388 is high with a CVSS score of 7.8.
The Aviatrix VPN Client through version 2.2.10 on Windows and Linux is affected.
A local attacker can exploit CVE-2019-17388 by gaining elevated privileges through file modifications in the Aviatrix VPN Client installation directory.
No, FreeBSD and Linux are not vulnerable to CVE-2019-17388.