Privilege Escalation in Tunnelblick by Google
CVE-2012-4677

Currently unrated

Key Information:

Vendor
Google
Vendor
CVE Published:
26 August 2012

Summary

A flaw in Tunnelblick versions prior to 3.3beta20 allows local users to gain elevated privileges through manipulation of the Info.plist file. An attacker can exploit this vulnerability by altering the gOkIfNotSecure value, which grants them unauthorized access to restricted functions.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.