CVE-2017-16637
Last modified
CVE-2017-16637 is a vulnerability of currently unknown severity. In Vectura Perfect Privacy VPN Manager v1.10.10 and v1.10.11, when resetting the network data via the software client, with a running VPN connection, a critical error occurs which leads to a "FrmAdvancedProtection" crash. Although the mechanism malfunctions and an error occurs during the runtime with the stack trace being issued, the software process is not properly terminated. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
In Vectura Perfect Privacy VPN Manager v1.10.10 and v1.10.11, when resetting the network data via the software client, with a running VPN connection, a critical error occurs which leads to a "FrmAdvancedProtection" crash. Although the mechanism malfunctions and an error occurs during the runtime with the stack trace being issued, the software process is not properly terminated. The software client is still attempting to maintain the connection even though the network connection information is being reset live. In that insecure mode, the "FrmAdvancedProtection" component crashes, but the process continues to run with different errors and process corruptions. This local corruption vulnerability can be exploited by local attackers.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Perfect-Privacy | Vpn Manager | 1.10.10 |
| Perfect-Privacy | Vpn Manager | 1.10.11 |
References
- https://board.perfect-privacy.com/threads/reporting-a-security-bug-in-vpn-software-client-for-windows.2223/Issue Tracking, Vendor Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2102Issue Tracking, Third Party Advisory
- https://board.perfect-privacy.com/threads/reporting-a-security-bug-in-vpn-software-client-for-windows.2223/Issue Tracking, Vendor Advisory
- https://www.vulnerability-lab.com/get_content.php?id=2102Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16637?
How severe is CVE-2017-16637?
How do I fix CVE-2017-16637?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-16631In SapphireIMS 4097_1, a guest user is able to change the pa…6.5
- CVE-2017-16632In SapphireIMS 4097_1, the password in the database is store…7.5
- CVE-2017-16633In Joomla! before 3.8.2, a logic bug in com_fields exposed r…
- CVE-2017-16634In Joomla! before 3.8.2, a bug allowed third parties to bypa…
- CVE-2017-16635In TinyWebGallery v2.4, an XSS vulnerability is located in t…
- CVE-2017-16636In Bludit v1.5.2 and v2.0.1, an XSS vulnerability is located…
- CVE-2017-16638The Gentoo net-misc/vde package before version 2.3.2-r4 may …
- CVE-2017-16639Tor Browser on Windows before 8.0 allows remote attackers to…
- CVE-2017-1664IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weak…
- CVE-2017-16641lib/rrd.php in Cacti 1.1.27 allows remote authenticated admi…
- CVE-2017-16642In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.…
- CVE-2017-16643The parse_hid_report_descriptor function in drivers/input/ta…
Are you affected by CVE-2017-16637?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
