PT-2026-5808 · Bartvpn · Bartvpn
CVE-2019-25275
·
Publicado
2026-02-04
·
Atualizado
2026-02-05
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BartVPN version 1.2.2
Description
BartVPN version 1.2.2 has an unquoted service path issue in the
BartVPNService. This allows local attackers to potentially run arbitrary code with higher system rights. Attackers can take advantage of the unquoted binary path by putting malicious executables in certain file system locations to take control of the service’s execution environment.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the
BartVPNService to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bartvpn