Unquoted Search Path or Element in Forcepoint VPN Client for Windows - CVE-2019-6145
Published: September 26, 2019
Forcepoint VPN Client for Windows
Forcepoint
Description
The vulnerability allows a local user to escalate privilege on the system.
The vulnerability exists due to software tries to execute programs in the following locations, when the VPN client is started:
- "C:\Program.exe"
- "C:\Program Files (x86)\Forcepoint\VPN.exe"
A local user with ability to place malicious binaries into these directories can execute arbitrary code on the system with SYSTEM privileges.