Weak File Permission in Aviatrix VPN Client allows Arbitrary Code Execution
CVE-2019-17388
7.8HIGH
Summary
The Aviatrix VPN Client has been found to have weak file permissions in its installation directory on both Windows and Linux platforms. This flaw enables a local attacker to manipulate files, potentially allowing them to execute arbitrary code by gaining elevated privileges. Such vulnerabilities highlight the importance of implementing stringent permission controls to safeguard sensitive applications from unauthorized access and exploits.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved