CVE-2017-20107

A vulnerability, which was classified as problematic, was found in ShadeYouVPN.com Client 2.0.1.11. Affected is an unknown function. The manipulation leads to improper privilege management. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.1.12 is able to address this issue. It is recommended to upgrade the affected component.
References
Link Resource
http://seclists.org/fulldisclosure/2017/Feb/28 Exploit Mailing List Third Party Advisory
https://vuldb.com/?id.97122 Permissions Required
http://seclists.org/fulldisclosure/2017/Feb/28 Exploit Mailing List Third Party Advisory
https://vuldb.com/?id.97122 Permissions Required
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:shadeyouvpn.com_project:shadeyouvpn.com:2.0.1.11:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:22

Type Values Removed Values Added
CVSS v2 : 7.2
v3 : 7.8
v2 : 7.2
v3 : 5.3
References () http://seclists.org/fulldisclosure/2017/Feb/28 - Exploit, Mailing List, Third Party Advisory () http://seclists.org/fulldisclosure/2017/Feb/28 - Exploit, Mailing List, Third Party Advisory
References () https://vuldb.com/?id.97122 - Permissions Required () https://vuldb.com/?id.97122 - Permissions Required

11 Jul 2022, 13:15

Type Values Removed Values Added
References (N/A) https://vuldb.com/?id.97122 - (N/A) https://vuldb.com/?id.97122 - Permissions Required
References (N/A) http://seclists.org/fulldisclosure/2017/Feb/28 - (N/A) http://seclists.org/fulldisclosure/2017/Feb/28 - Exploit, Mailing List, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
CWE CWE-269
CPE cpe:2.3:a:shadeyouvpn.com_project:shadeyouvpn.com:2.0.1.11:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

28 Jun 2022, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-28 07:15

Updated : 2024-11-21 03:22


NVD link : CVE-2017-20107

Mitre link : CVE-2017-20107

CVE.ORG link : CVE-2017-20107


JSON object : View

Products Affected

shadeyouvpn.com_project

  • shadeyouvpn.com

microsoft

  • windows
CWE
CWE-269

Improper Privilege Management