Description
Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower privileged users to replace the VPN executable with a malicious one. When a higher privileged user such as an Administrator launches that executable, it is possible for the lower privileged user to escalate to Administrator privileges.
Published: 2021-12-30
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-31303 Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower privileged users to replace the VPN executable with a malicious one. When a higher privileged user such as an Administrator launches that executable, it is possible for the lower privileged user to escalate to Administrator privileges.
History

No history.

Subscriptions

Leap Bitmask Riseup Vpn
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2024-08-04T04:25:16.432Z

Reserved: 2021-12-30T00:00:00.000Z

Link: CVE-2021-44466

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-30T22:15:09.957

Modified: 2024-11-21T06:31:02.027

Link: CVE-2021-44466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses