Privilege Escalation Vulnerability in Pritunl Client by Pritunl
CVE-2025-43917

8.2HIGH

Key Information:

Vendor

Pritunl

Vendor
CVE Published:
19 April 2025

What is CVE-2025-43917?

A privilege escalation vulnerability in Pritunl Client versions prior to 1.3.4220.57 allows an administrator with access to specific application directories to exploit the uninstall process. Once the application is uninstalled, the administrator can inject a file into the location of the removed pritunl-service file. This injected file can be executed with root privileges through a LaunchDaemon, potentially compromising system integrity and security.

Affected Version(s)

Pritunl-Client 0 < 1.3.4220.57

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
The Cyber Security Vulnerability Database.