CVE-2021-31776 Information

Description

Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://docs.aviatrix.com/Downloads/samlclient.html https://docs.aviatrix.com/Downloads/samlclient.html#windows-win https://docs.aviatrix.com/HowTos/changelog.html#aviatrix-vpn-client-changelog

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: