CVE-2017-17809
Last modified
CVE-2017-17809 is a vulnerability of currently unknown severity. In Golden Frog VyprVPN before 2.15.0.5828 for macOS, the vyprvpnservice launch daemon has an unprotected XPC service that allows attackers to update the underlying OpenVPN configuration and the arguments passed to the OpenVPN binary when executed. An attacker can abuse this vulnerability by forcing the VyprVPN application to load a malicious dynamic library every time a new connection is made.. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
In Golden Frog VyprVPN before 2.15.0.5828 for macOS, the vyprvpnservice launch daemon has an unprotected XPC service that allows attackers to update the underlying OpenVPN configuration and the arguments passed to the OpenVPN binary when executed. An attacker can abuse this vulnerability by forcing the VyprVPN application to load a malicious dynamic library every time a new connection is made.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Goldenfrog | Vyprvpn | < 2.15.0.5828 |
References
- https://github.com/VerSprite/research/blob/master/advisories/VS-2017-007.mdThird Party Advisory
- https://github.com/VerSprite/research/blob/master/advisories/VS-2017-007.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17809?
How severe is CVE-2017-17809?
How do I fix CVE-2017-17809?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-17802In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIR…
- CVE-2017-17803In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIR…
- CVE-2017-17804In IKARUS anti.virus 2.16.20, the driver file (ntguard.SYS) …
- CVE-2017-17805The Salsa20 encryption algorithm in the Linux kernel before …7.8
- CVE-2017-17806The HMAC implementation (crypto/hmac.c) in the Linux kernel …7.8
- CVE-2017-17807The KEYS subsystem in the Linux kernel before 4.14.6 omitted…
- CVE-2017-17810In Netwide Assembler (NASM) 2.14rc0, there is a "SEGV on unk…
- CVE-2017-17811In Netwide Assembler (NASM) 2.14rc0, there is a heap-based b…
- CVE-2017-17812In Netwide Assembler (NASM) 2.14rc0, there is a heap-based b…
- CVE-2017-17813In Netwide Assembler (NASM) 2.14rc0, there is a use-after-fr…
- CVE-2017-17814In Netwide Assembler (NASM) 2.14rc0, there is a use-after-fr…
- CVE-2017-17815In Netwide Assembler (NASM) 2.14rc0, there is an illegal add…
Are you affected by CVE-2017-17809?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
