An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafted configuration file can cause a privilege escalation, resulting in the execution of arbitrary commands with system privileges.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HNordvpn
APPNordvpn6.14.28.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPEVPNCommand Injection
CWE
Related vulnerabilities
CVE-2018-10170CRITICAL9.8PL ✓same product
NordVPN – privilege escalation do SYSTEM przez usługę nordvpn-service
CVE-2018-9105HIGH8.8same product
NordVPN 3.3.10 for macOS suffers from a root privilege escalation vulnerability. The vulnerability stems from ...
CVE-2019-25572MEDIUM6.9same product
NordVPN 6.19.6 zawiera lukę denial of service, która pozwala lokalnym atakującym na zawieszenie aplikacji popr...