Description
NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification.
Problem types
Incorrect Permission Assignment for Critical Resource
Product status
Credits
SajjadBnd
References
www.exploit-db.com/exploits/47831 (ExploitDB-47831)
vm3max.site (Vendor Homepage)
www.vulncheck.com/...ories/nextvpn-insecure-file-permissions (VulnCheck Advisory: NextVPN v4.10 - Insecure File Permissions)