An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.pango.co/sec31944/ |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T12:04:22.936Z
Reserved: 2020-05-13T00:00:00
Link: CVE-2020-12828
No data.
Status : Modified
Published: 2020-05-21T17:15:10.227
Modified: 2024-11-21T05:00:21.300
Link: CVE-2020-12828
No data.
OpenCVE Enrichment
No data.
Weaknesses