CVE-2020-25989
Summary
| CVE | CVE-2020-25989 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-19 21:15:00 UTC |
| Updated | 2022-06-02 18:45:00 UTC |
| Description | Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code on the effected system with root privileges. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pritunl | Pritunl-client-electron | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Arbitrary File Write in Pritunl (CVE 2020-25989) | vuln-disclosures | MISC | vkas-afk.github.io | Exploit, Third Party Advisory |
| Remove file before io write file · pritunl/pritunl-client-electron@89f8c99 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.