CVE-2017-16637 Information
Description
In Vectura Perfect Privacy VPN Manager v1.10.10 and v1.10.11 when resetting the network data via the software client with a running VPN connection a critical error occurs which leads to a \FrmAdvancedProtection\ crash. Although the mechanism malfunctions and an error occurs during the runtime with the stack trace being issued the software process is not properly terminated. The software client is still attempting to maintain the connection even though the network connection information is being reset live. In that insecure mode the \FrmAdvancedProtection\ component crashes but the process continues to run with different errors and process corruptions. This local corruption vulnerability can be exploited by local attackers.
CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Reference
https://board.perfect-privacy.com/threads/reporting-a-security-bug-in-vpn-software-client-for-windows.2223/ https://www.vulnerability-lab.com/get_content.php?id=2102
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
4.4
Share on: