Security Advisory

CVE-2018-3952

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-09-07 15:00:00
Last updated 2024-09-16 17:28:50
Assigner talos
CVSS score 8.8
State PUBLISHED

Description

An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafted configuration file can cause a privilege escalation, resulting in the execution of arbitrary commands with system privileges.