First published: Thu May 21 2020(Updated: )
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Pango Virtual Private Network Software Development Kit | <1.3.3.218 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.