CVE-2025-26169: Race Condition
IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26169?
CVE-2025-26169 is classified as a local privilege escalation vulnerability with a high severity due to its potential impact on system security.
How do I fix CVE-2025-26169?
To fix CVE-2025-26169, users should upgrade the IXON VPN Client to version 1.4.4 or later.
Who is affected by CVE-2025-26169?
CVE-2025-26169 affects users of IXON VPN Client versions prior to 1.4.4 on Windows.
What type of vulnerability is CVE-2025-26169?
CVE-2025-26169 is a local privilege escalation vulnerability that enables code execution due to insecure handling of configuration files.
Can a low-privileged user exploit CVE-2025-26169?
Yes, a low-privileged user can exploit CVE-2025-26169 due to a race condition involving a world-writable temporary configuration file.