Vulnerabilities (CVE)

Filtered by vendor Pango Subscribe
Filtered by product Virtual Private Network Software Development Kit
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-12828 1 Pango 1 Virtual Private Network Software Development Kit 2023-12-10 10.0 HIGH 9.8 CRITICAL
An issue was discovered in AnchorFree VPN SDK before 1.3.3.218. The VPN SDK service takes certain executable locations over a socket bound to localhost. Binding to the socket and providing a path where a malicious executable file resides leads to executing the malicious executable file with SYSTEM privileges.