Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allows a local user to corrupt system files: a local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-09-24T22:25:50

Updated: 2024-08-04T13:53:16.955Z

Reserved: 2020-08-05T00:00:00

Link: CVE-2020-17365

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-09-24T23:15:13.977

Modified: 2020-10-09T16:28:37.243

Link: CVE-2020-17365

cve-icon Redhat

No data.