NextVPN Insecure File Permissions Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability in NextVPN version 4.10 has been identified, stemming from insecure file permissions that enable local users to modify executable files with full access rights. This flaw allows unauthorized alteration of system executables, which can be replaced with malicious files to gain SYSTEM or Administrator privileges.
Impact
Exploitation of this vulnerability could lead to unauthorized modification of executable files, allowing for the replacement of legitimate system executables with malicious ones. This could result in elevated privileges, granting SYSTEM or Administrator rights.
Reproduction
The vulnerability can be reproduced by replacing any of the NextVPN executable files, such as NextVPN.exe or Helper64.exe, with a malicious executable. After the replacement, the application can be launched, and the user will gain SYSTEM or Administrator privileges.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
