Protonvpn 1.26.0 unquoted service path Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2022-03-23 |
Type : local |
Platform : windows
This exploit / vulnerability Protonvpn 1.26.0 unquoted service path is for educational purposes only and if it is used you will do on your own risk!
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
If a malicious individual has access to the file system, it is possible to elevate privileges by inserting such a file as "C:\Program.exe" to be run by a privileged program making use of WinExec.