CVE-2020-12828: Malicious File Upload
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12828?
CVE-2020-12828 is classified as a critical vulnerability due to its potential for executing malicious code with SYSTEM privileges.
How do I fix CVE-2020-12828?
To fix CVE-2020-12828, update the AnchorFree VPN SDK to version 1.3.3.218 or later.
What are the potential impacts of CVE-2020-12828?
The potential impacts of CVE-2020-12828 include unauthorized access to system resources and execution of malicious code on affected systems.
Which versions of AnchorFree VPN SDK are vulnerable to CVE-2020-12828?
Versions of AnchorFree VPN SDK prior to 1.3.3.218 are vulnerable to CVE-2020-12828.
Is my system at risk if I use an outdated AnchorFree VPN SDK?
Yes, using an outdated AnchorFree VPN SDK version prior to 1.3.3.218 puts your system at significant risk of exploitation due to CVE-2020-12828.