← Back to CVE List

CVE-2021-35523

Published: 2021-06-28T17:15Z
Last Modified: 2024-11-21T06:12Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt