CVE-2024-37391

ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:proton:protonvpn:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 09:23

Type Values Removed Values Added
References () https://github.com/ProtonVPN/win-app/commit/2e4e25036842aaf48838c6a59f14671b86c20aa7 - Patch () https://github.com/ProtonVPN/win-app/commit/2e4e25036842aaf48838c6a59f14671b86c20aa7 - Patch
References () https://github.com/ProtonVPN/win-app/compare/3.2.9...3.2.10 - Patch () https://github.com/ProtonVPN/win-app/compare/3.2.9...3.2.10 - Patch

31 Jul 2024, 18:33

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.8

25 Jul 2024, 15:13

Type Values Removed Values Added
References () https://github.com/ProtonVPN/win-app/commit/2e4e25036842aaf48838c6a59f14671b86c20aa7 - () https://github.com/ProtonVPN/win-app/commit/2e4e25036842aaf48838c6a59f14671b86c20aa7 - Patch
References () https://github.com/ProtonVPN/win-app/compare/3.2.9...3.2.10 - () https://github.com/ProtonVPN/win-app/compare/3.2.9...3.2.10 - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE NVD-CWE-noinfo
First Time Proton protonvpn
Proton
Microsoft
Microsoft windows
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:proton:protonvpn:*:*:*:*:*:*:*:*

22 Jul 2024, 13:00

Type Values Removed Values Added
Summary
  • (es) ProtonVPN anterior a 3.2.10 en Windows maneja mal la ruta del instalador de la unidad, que debería usar esto: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' en Setup/setup.iss.

22 Jul 2024, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-22 07:15

Updated : 2024-11-21 09:23


NVD link : CVE-2024-37391

Mitre link : CVE-2024-37391

CVE.ORG link : CVE-2024-37391


JSON object : View

Products Affected

proton

  • protonvpn

microsoft

  • windows