Link following in VPN Proxy One Pro - CVE-2024-41183
Published: July 23, 2024 / Updated: August 5, 2024
VPN Proxy One Pro
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to insecure link following within the DEP Manager and VpnBackgroundController executable. A local user can create a symbolic link to a critical file on the system and execute arbitrary code with SYSTEM privileges.