CVE-2018-11479
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 11%
from disclosure to weapon623 days
Published on NVDMay 25
1st PoC+623d
metasploitMay 24
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.). There is no validation of the program name before constructing the lpCommandLine argument for a CreateProcess call. An attacker can run any malicious process with SYSTEM privileges through this named pipe.
Affected products
n/a · n/apublic PoCs found — 2✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/48021cve_referencepacketstormsecurity.com/files/156222/Windscribe-WindscribeService-Named-Pipe-Privilege-Escalation.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.