Local Privilege Escalation in IXON VPN Client on Windows
CVE-2025-26169

8.1HIGH

Key Information:

Vendor

Ixon

Vendor
CVE Published:
7 May 2025

What is CVE-2025-26169?

The IXON VPN Client prior to version 1.4.4 on Windows contains a local privilege escalation vulnerability that permits low-privileged users to execute arbitrary code with elevated privileges. This occurs through the manipulation of a configuration file that resides in a world-writable directory. An attacker can exploit a race condition, allowing them to overwrite a temporary configuration file, gaining unintended access to SYSTEM-level privileges. Users are advised to update to the latest version to mitigate this risk.

Affected Version(s)

VPN Client 0 < 1.4.4

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.