Unquoted Search Path Vulnerability in Forcepoint VPN Client for Windows
CVE-2019-6145
6.7MEDIUM
What is CVE-2019-6145?
The Forcepoint VPN Client for Windows prior to version 6.6.1 is susceptible to an unquoted search path vulnerability. This flaw allows local users to potentially escalate their privileges to that of the SYSTEM user, provided they have write access to certain vulnerable directories. This is particularly concerning as it enables the execution of malicious executables in a manner that could compromise system security. Forcepoint has acknowledged the discovery of this vulnerability, credited to Peleg Hadar of SafeBreach Labs, ensuring that users are made aware and can take necessary precautions.
Affected Version(s)
Forcepoint VPN Client for Windows versions earlier than 6.6.1