CVE-2021-31776

Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:aviatrix:vpn_client:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:06

Type Values Removed Values Added
References () https://docs.aviatrix.com/Downloads/samlclient.html - Product, Vendor Advisory () https://docs.aviatrix.com/Downloads/samlclient.html - Product, Vendor Advisory
References () https://docs.aviatrix.com/Downloads/samlclient.html#windows-win - Product, Vendor Advisory () https://docs.aviatrix.com/Downloads/samlclient.html#windows-win - Product, Vendor Advisory
References () https://docs.aviatrix.com/HowTos/changelog.html#aviatrix-vpn-client-changelog - Release Notes, Vendor Advisory () https://docs.aviatrix.com/HowTos/changelog.html#aviatrix-vpn-client-changelog - Release Notes, Vendor Advisory

Information

Published : 2021-04-29 01:15

Updated : 2024-11-21 06:06


NVD link : CVE-2021-31776

Mitre link : CVE-2021-31776

CVE.ORG link : CVE-2021-31776


JSON object : View

Products Affected

microsoft

  • windows

aviatrix

  • vpn_client
CWE
CWE-428

Unquoted Search Path or Element