First published: Tue May 04 2021(Updated: )
All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openvpn options to execute code as root/SYSTEM.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Windscribe | <=2.02.10 | |
Windscribe | <=2.02.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27518 is classified as a local privilege escalation vulnerability.
To fix CVE-2020-27518, update Windscribe VPN to a version later than 2.02.10.
CVE-2020-27518 affects all versions of Windscribe VPN for Mac and Windows up to version 2.02.10.
An attacker can leverage CVE-2020-27518 to execute code with root or SYSTEM privileges.
Yes, CVE-2020-27518 specifically affects Windscribe VPN on Mac and Windows platforms.