VPN Flaw Allows Criminal Access to Everything on Victims Computers

  /     /     /  
Publicated : 23/11/2024   Category : security


VPN Flaw Allows Criminal Access to Everything on Victims Computers


Vulnerability in the Aviatrix VPN client, since patched, gives an attacker unlimited access to a breached system.



A VPN vulnerability that provided both initial access to a victims computer and privilege escalation once access was granted has been disclosed. The vulnerability in the Aviatrix VPN client, used by large organizations such as NASA and Shell,
has been patched
in all versions and is available for download.
Immersive Labs researcher and content engineer Alex Seymour discovered the vulnerability in early October. After noting evidence that a pair of Web servers were launched during the VPN clients open sequence, he found the servers and the Python used to create them had known issues, especially with the very lax permissions given the servers during the sequence.
Seymour was able to show proof of the privilege escalation that would allow an attacker to run essentially any random code desired on the targeted machine. Aviatrix responded to the notice of the breach and patched the vulnerability in less than a month. Both Aviatrix and Seymour recommend that all Aviatrix VPN client users update to the latest version as soon as possible.
Read more 
here
.
Check out 
The Edge
, Dark Readings new section for features, threat data, and in-depth perspectives. Todays top story:
10 Security Chestnuts We Should Roast Over the Open Fire
.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
VPN Flaw Allows Criminal Access to Everything on Victims Computers