EIP-2026-120698

PRE-CVE

ProtonVPN v4.4.1 - Unquoted Service Path

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-120698. PoCs published by Milad karimi.

AI-analyzed exploit summary This exploit describes an unquoted service path vulnerability in ProtonVPN v4.4.1, where the service binary path contains spaces but lacks quotes, allowing a local attacker to escalate privileges by placing a malicious executable in a predictable path (e.g., C:\Program.exe). The PoC demonstrates querying the vulnerable service configuration via `sc.exe`.

Description

ProtonVPN v4.4.1 - Unquoted Service Path

Exploits (1)

exploitdb WRITEUP
by Milad karimi · textlocalwindows
https://www.exploit-db.com/exploits/52624

This exploit describes an unquoted service path vulnerability in ProtonVPN v4.4.1, where the service binary path contains spaces but lacks quotes, allowing a local attacker to escalate privileges by placing a malicious executable in a predictable path (e.g., C:\Program.exe). The PoC demonstrates querying the vulnerable service configuration via `sc.exe`.

Classification
Writeup 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: ProtonVPN v4.4.1
Auth required
Prerequisites: Local access to the target system · Ability to write to the system root path or a directory earlier in the service path (e.g., C:\Program.exe) · Privileges to restart the service or reboot the system
mistral-large-3 · analyzed Jul 08, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Jul 08, 2026