Unquoted Search Path or Element in Forcepoint VPN Client for Windows - CVE-2019-6145

 

Unquoted Search Path or Element in Forcepoint VPN Client for Windows - CVE-2019-6145

Published: September 26, 2019


Vulnerability identifier: #VU21348
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6145
CWE-ID: CWE-428
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privilege on the system.

The vulnerability exists due to software tries to execute programs in the following locations, when the VPN client is started:

  • "C:\Program.exe"
  • "C:\Program Files (x86)\Forcepoint\VPN.exe"

A local user with ability to place malicious binaries into these directories can execute arbitrary code on the system with SYSTEM privileges.


Affected software

Forcepoint VPN Client for Windows

How to mitigate CVE-2019-6145

Install updates from vendor's website.

Forcepoint VPN Client for Windows - update to 6.6.1

External References

Related Security Bulletins