{"api_version":"1","generated_at":"2026-07-23T12:35:22+00:00","cve":"CVE-2020-25989","urls":{"html":"https://cve.report/CVE-2020-25989","api":"https://cve.report/api/cve/CVE-2020-25989.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-25989","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-25989"},"summary":{"title":"CVE-2020-25989","description":"Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code on the effected system with root privileges.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-11-19 21:15:00","updated_at":"2022-06-02 18:45:00"},"problem_types":["CWE-59"],"metrics":[],"references":[{"url":"https://vkas-afk.github.io/vuln-disclosures/","name":"https://vkas-afk.github.io/vuln-disclosures/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Arbitrary File Write in Pritunl (CVE 2020-25989) | vuln-disclosures","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/pritunl/pritunl-client-electron/commit/89f8c997c6f93e724f68f76f7f47f8891d9acc2d","name":"https://github.com/pritunl/pritunl-client-electron/commit/89f8c997c6f93e724f68f76f7f47f8891d9acc2d","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"Remove file before io write file · pritunl/pritunl-client-electron@89f8c99 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-25989","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-25989","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"25989","vulnerable":"1","versionEndIncluding":"1.2.2550.20","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pritunl","cpe5":"pritunl-client-electron","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-25989","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code on the effected system with root privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://vkas-afk.github.io/vuln-disclosures/","url":"https://vkas-afk.github.io/vuln-disclosures/"},{"refsource":"CONFIRM","name":"https://github.com/pritunl/pritunl-client-electron/commit/89f8c997c6f93e724f68f76f7f47f8891d9acc2d","url":"https://github.com/pritunl/pritunl-client-electron/commit/89f8c997c6f93e724f68f76f7f47f8891d9acc2d"}]}},"nvd":{"publishedDate":"2020-11-19 21:15:00","lastModifiedDate":"2022-06-02 18:45:00","problem_types":["CWE-59"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":7.2},"severity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pritunl:pritunl-client-electron:*:*:*:*:*:*:*:*","versionStartIncluding":"1.0.1116.6","versionEndIncluding":"1.2.2550.20","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"25989","Ordinal":"187407","Title":"CVE-2020-25989","CVE":"CVE-2020-25989","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"25989","Ordinal":"1","NoteData":"Privilege escalation via arbitrary file write in pritunl electron client 1.0.1116.6 through v1.2.2550.20. Successful exploitation of the issue may allow an attacker to execute code on the effected system with root privileges.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"25989","Ordinal":"2","NoteData":"2020-11-19","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"25989","Ordinal":"3","NoteData":"2020-11-19","Type":"Other","Title":"Modified"}]}}}