7.8
CVSSv3

CVE-2020-27519

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: 7.2 | VMScore: 880 | EPSS: 0.00044 | KEV: Not Included
Published: 30/04/2021 Updated: 21/11/2024

Vulnerability Summary

Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker could leverage the log and log-append along with log injection to create or append to privileged script files and execute code as root/SYSTEM.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pritunl pritunl-client-electron 1.2.2550.20