Untrusted search path in Mobile VPN with SSL for Windows - CVE-2025-1549
Published: October 29, 2025
Mobile VPN with SSL for Windows
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path. A local user can place a malicious binary into a specific location on the system and execute arbitrary code with escalated privileges.
Note, the vulnerability exists due to incomplete fix for #VU117788 (CVE-2024-4944).