The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or repair.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://cyvisory.group/advisory/CYADV-2023-012 | broken link |
https://sourceforge.net/p/securepoint/news/2023/08/2040-is-now-available/ | third party advisory |