Back to search
CVE-2021-35523
Published: Jun 28, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20210629 CVE-2021-35523: Local Privilege Escalation in Securepoint SSL VPN Client 2.0.30
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now