AtlasVPN privilege escalation | CVE-2022-23171
NAME
AtlasVPN privilege escalation
- Platforms Affected:
AtlasVPN AtlasVPN 2.4 - Risk Level:
8 - Exploitability:
Unproven - Consequences:
Gain Privileges
DESCRIPTION
AtlasVPN could allow a remote authenticated attacker to gain elevated privileges on the system, caused by improper security controls on named pipe messages. By sending a specially-crafted payload, an authenticated attacker could exploit this vulnerability to gain elevated privileges with SYSTEM permissions.
CVSS 3.0 Information
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Access Vector: Adjacent Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of AtlasVPN (2.4.2 or later), available from the AtlasVPN Web site. See References.
- Reference Link:
https://www.gov.il/en/departments/faq/cve_advisories - Reference Link:
https://atlasvpn.com
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.