Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker could leverage the log and log-append along with log injection to create or append to privileged script files and execute code as root/SYSTEM.
{
"cpe": "cpe:2.3:a:pritunl:pritunl-client-electron:1.2.2550.20:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "1.2.2550.20"
},
{
"last_affected": "1.2.2550.20"
}
],
"source": [
"CPE_STRING",
"REFERENCES"
]
}