NordVPN Unquoted Service Path Vulnerability in nordvpn-service Allowing Privilege Escalation

Vulnerability

A vulnerability has been identified in NordVPN version 6.31.13.0, specifically within the nordvpn-service component. This vulnerability arises from an unquoted service path, which local attackers can exploit to execute code with elevated privileges. By taking advantage of the unquoted binary path during system startup or reboot, it is possible to run malicious code with LocalSystem permissions.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution with elevated privileges, allowing local attackers to execute malicious payloads with LocalSystem rights.

Reproduction

The vulnerability can be reproduced by creating a service with an unquoted path that includes spaces. This can be done using the Windows Service Control (sc) command. Once the service is set up, it can be exploited by placing a malicious executable in a directory that is referenced by the service path. When the system starts or reboots, the service will execute the malicious code with elevated privileges.

Added: Jan 28, 2026, 1:28 PM
Updated: Jan 28, 2026, 1:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.5
remediation
0.0
relevance
2.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.