CVE-2023-50446: High severity mullvad vpn client vulnerability
Published Dec 10, 2023
·Updated
An issue was discovered in Mullvad VPN Windows app before 2023.6-beta1. Insufficient permissions on a directory allow any local unprivileged user to escalate privileges to SYSTEM.
Affected Software
1 affected component
Mullvad Mullvad VPN Windows<=2023.5
Remediation
Patch Available
Event History
Dec 10, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-50446?
CVE-2023-50446 is considered a critical vulnerability due to its potential for privilege escalation to SYSTEM level access.
2
How do I fix CVE-2023-50446?
To mitigate CVE-2023-50446, update the Mullvad VPN Windows app to version 2023.6-beta1 or later.
3
Who is affected by CVE-2023-50446?
CVE-2023-50446 affects all users of Mullvad VPN Windows app versions prior to 2023.6-beta1.
4
What type of vulnerability is CVE-2023-50446?
CVE-2023-50446 is a privilege escalation vulnerability caused by insufficient permissions on a directory.
5
Is there a workaround for CVE-2023-50446?
The best approach for CVE-2023-50446 is to update to the latest version, as there are no known workarounds.