An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.pango.co/sec31944/ | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2020-05-21 17:15
Updated : 2020-06-02 16:55
NVD link : CVE-2020-12828
Mitre link : CVE-2020-12828
CVE.ORG link : CVE-2020-12828
JSON object : View
Products Affected
                pango
- virtual_private_network_software_development_kit
 
CWE
                
                    
                        
                        CWE-434
                        
            Unrestricted Upload of File with Dangerous Type
