Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower privileged users to replace the VPN executable with a malicious one. When a higher privileged user such as an Administrator launches that executable, it is possible for the lower privileged user to escalate to Administrator privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-04T04:25:16.432Z

Reserved: 2021-12-30T00:00:00

Link: CVE-2021-44466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-30T22:15:09.957

Modified: 2024-11-21T06:31:02.027

Link: CVE-2021-44466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.