Description
A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileges on the Windows system. This vulnerability is an additional unmitigated attack path for CVE-2024-4944. This vulnerability is resolved in the Mobile VPN with SSL client for Windows version 12.11.3
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
Any version
Credits
Defence Tech Malware Lab
References
www.watchguard.com/wgrd-psirt/advisory/wgsa-2025-00016