Local Privilege Escalation in IXON VPN Client on Windows
CVE-2025-26169
8.1HIGH
What is CVE-2025-26169?
The IXON VPN Client prior to version 1.4.4 on Windows contains a local privilege escalation vulnerability that permits low-privileged users to execute arbitrary code with elevated privileges. This occurs through the manipulation of a configuration file that resides in a world-writable directory. An attacker can exploit a race condition, allowing them to overwrite a temporary configuration file, gaining unintended access to SYSTEM-level privileges. Users are advised to update to the latest version to mitigate this risk.
Affected Version(s)
VPN Client 0 < 1.4.4
