CVE-2021-35523
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.73%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.73% probability · 52th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- securepoint/openvpn-client
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/163320/Securepoint-SSL-VPN-Client-2.0.30-Local-Privilege-Escalation.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2021/Jun/59Mailing List, Third Party Advisory
- https://bogner.sh/2021/04/local-privilege-escalation-in-securepoint-ssl-vpn-client-2-0-30/Exploit, Third Party Advisory
- https://github.com/Securepoint/openvpn-client/security/advisories/GHSA-v8p8-4w8f-qh34Third Party Advisory
- http://packetstormsecurity.com/files/163320/Securepoint-SSL-VPN-Client-2.0.30-Local-Privilege-Escalation.htmlExploit, Third Party Advisory
- http://seclists.org/fulldisclosure/2021/Jun/59Mailing List, Third Party Advisory
- https://bogner.sh/2021/04/local-privilege-escalation-in-securepoint-ssl-vpn-client-2-0-30/Exploit, Third Party Advisory
- https://github.com/Securepoint/openvpn-client/security/advisories/GHSA-v8p8-4w8f-qh34Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.