EIP-2026-117272

PRE-CVE

Hide.Me VPN Client 1.2.4 - Local Privilege Escalation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-117272. PoCs published by sh4d0wman.

AI-analyzed exploit summary This writeup describes an elevation of privilege (EoP) vulnerability in Hide.Me VPN Client 1.2.4 due to insecure default permissions on the installation directory, allowing a local user to replace binaries or DLLs to escalate to SYSTEM privileges.

Description

Hide.Me VPN Client 1.2.4 - Local Privilege Escalation

Exploits (1)

exploitdb WRITEUP
by sh4d0wman · textlocalwindows
https://www.exploit-db.com/exploits/40071

This writeup describes an elevation of privilege (EoP) vulnerability in Hide.Me VPN Client 1.2.4 due to insecure default permissions on the installation directory, allowing a local user to replace binaries or DLLs to escalate to SYSTEM privileges.

Classification
Writeup 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Hide.Me VPN Client 1.2.4
Auth required
Prerequisites: Local user access · Hide.Me VPN Client 1.2.4 installed · Ability to reboot the machine
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026