CVE-2018-10190
Last modified
CVE-2018-10190 is a vulnerability of currently unknown severity. A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run executable files with elevated privileges. The vulnerability is due to insufficient implementation of access controls. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run executable files with elevated privileges. The vulnerability is due to insufficient implementation of access controls. The "Changelog" and "Help" options available from the system tray context menu spawn an elevated instance of the user's default web browser. An attacker could exploit this vulnerability by selecting "Run as Administrator" from the context menu of an executable file within the file browser of the spawned default web browser. This may allow the attacker to execute privileged commands on the targeted system.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Londontrustmedia | Private Internet Access | 77 |
References
- https://github.com/VerSprite/research/blob/master/advisories/VS-2018-019.mdThird Party Advisory
- https://github.com/VerSprite/research/blob/master/advisories/VS-2018-019.mdThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10190?
How severe is CVE-2018-10190?
How do I fix CVE-2018-10190?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-10185An issue was discovered in TuziCMS v2.0.6. There is a CSRF v…
- CVE-2018-10186In radare2 2.5.0, there is a heap-based buffer over-read in …
- CVE-2018-10187In radare2 2.5.0, there is a heap-based buffer over-read in …
- CVE-2018-10188phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attack…
- CVE-2018-10189An issue was discovered in Mautic 1.x and 2.x before 2.13.0.…
- CVE-2018-1019A remote code execution vulnerability exists in the way that…
- CVE-2018-10191In versions of mruby up to and including 1.4.0, an integer o…9.8
- CVE-2018-10192IPVanish 3.0.11 for macOS suffers from a root privilege esca…
- CVE-2018-10193LogMeIn LastPass through 4.15.0 allows remote attackers to c…
- CVE-2018-10194The set_text_distance function in devices/vector/gdevpdts.c …
- CVE-2018-10195lrzsz before version 0.12.21~rc can leak information to the …7.1
- CVE-2018-10196NULL pointer dereference vulnerability in the rebuild_vlists…
Are you affected by CVE-2018-10190?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
