Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25283. PoCs published by D.Goedecke.
AI-analyzed exploit summary This is a writeup describing an unquoted service path vulnerability in Shrew Soft VPN Client 2.2.2. The exploit details how a local user could potentially execute arbitrary code with elevated privileges by placing malicious executables in the system root path.
Description
Shrew Soft VPN Client 2.2.2 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can place malicious executables in the unquoted service path to gain elevated access during service startup or system reboot.
Exploits (1)
This is a writeup describing an unquoted service path vulnerability in Shrew Soft VPN Client 2.2.2. The exploit details how a local user could potentially execute arbitrary code with elevated privileges by placing malicious executables in the system root path.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H