CVE-2020-27518

HIGH

Description

All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openvpn options to execute code as root/SYSTEM.

References

https://jeffs.sh/CVEs/CVE-2020-27518.txt

http://windscribe.com

Details

Source: MITRE

Published: 2021-05-04

Updated: 2021-05-11

Type: CWE-269

Risk Information

CVSS v2.0

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

CVSS v3.0

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:windscribe:windscribe:*:*:*:*:*:macos:*:* versions up to 2.02.10: (inclusive)

cpe:2.3:a:windscribe:windscribe:*:*:*:*:*:windows:*:* versions up to 2.02.10: (inclusive)