github.com
https://github.com/hessandrew/CVE-2020-9442 CVE-2020-9442
HIGH
Record summary
CVE-2020-9442 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC.
Description
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Proofs of concept
1Repository PoCs
GitHubhessandrew/CVE-2020-9442Repository PoCby hessandrewStars: 25Not analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-9442