VPN Flaw Allows Criminal Access to Everything on Victims Computers

  /     /     /  
Publicated : 23/11/2024   Category : security


VPN Flaw Allows Criminal Access to Everything on Victims Computers


Vulnerability in the Aviatrix VPN client, since patched, gives an attacker unlimited access to a breached system.



A VPN vulnerability that provided both initial access to a victims computer and privilege escalation once access was granted has been disclosed. The vulnerability in the Aviatrix VPN client, used by large organizations such as NASA and Shell,
has been patched
in all versions and is available for download.
Immersive Labs researcher and content engineer Alex Seymour discovered the vulnerability in early October. After noting evidence that a pair of Web servers were launched during the VPN clients open sequence, he found the servers and the Python used to create them had known issues, especially with the very lax permissions given the servers during the sequence.
Seymour was able to show proof of the privilege escalation that would allow an attacker to run essentially any random code desired on the targeted machine. Aviatrix responded to the notice of the breach and patched the vulnerability in less than a month. Both Aviatrix and Seymour recommend that all Aviatrix VPN client users update to the latest version as soon as possible.
Read more 
here
.
Check out 
The Edge
, Dark Readings new section for features, threat data, and in-depth perspectives. Todays top story:
10 Security Chestnuts We Should Roast Over the Open Fire
.

Last News

▸ Beware EMV may not fully protect against skilled thieves. ◂
Discovered: 23/12/2024
Category: security

▸ Hack Your Hotel Room ◂
Discovered: 23/12/2024
Category: security

▸ Website hacks happened during World Cup final. ◂
Discovered: 23/12/2024
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
VPN Flaw Allows Criminal Access to Everything on Victims Computers