← Back to CVE List

CVE-2022-24141

Published: 2022-07-06T13:15Z
Last Modified: 2024-11-21T06:49Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing ImpersonateNamedPipeClient(). > MITRE Terms of Use apply – see LICENSE‑MITRE.txt