Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-120698. PoCs published by Milad karimi.
AI-analyzed exploit summary This exploit describes an unquoted service path vulnerability in ProtonVPN v4.4.1, where the service binary path contains spaces but lacks quotes, allowing a local attacker to escalate privileges by placing a malicious executable in a predictable path (e.g., C:\Program.exe). The PoC demonstrates querying the vulnerable service configuration via `sc.exe`.
Description
ProtonVPN v4.4.1 - Unquoted Service Path
Exploits (1)
This exploit describes an unquoted service path vulnerability in ProtonVPN v4.4.1, where the service binary path contains spaces but lacks quotes, allowing a local attacker to escalate privileges by placing a malicious executable in a predictable path (e.g., C:\Program.exe). The PoC demonstrates querying the vulnerable service configuration via `sc.exe`.