Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-09-24T22:25:50
Updated: 2024-08-04T13:53:16.955Z
Reserved: 2020-08-05T00:00:00
Link: CVE-2020-17365
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-09-24T23:15:13.977
Modified: 2024-11-21T05:07:57.323
Link: CVE-2020-17365
Redhat
No data.