carolcoral / no-free_vpn

亲测可用的 VPN。亲测有效的科学上网,同时支持 windows、mac、linux、ios 和 andrioid 系统。并提供 chrome、firefox、opera 等浏览器的插件使用。
https://carolcoral.github.io/no-free_vpn/
811 stars 120 forks source link

Unquoted service path #19

Closed Mohad0 closed 3 years ago

Mohad0 commented 3 years ago

Hi no-free_vpn team,

After installing no-free_vpn 2.5.1 from https://github.com/carolcoral/no-free_vpn/releases/download/BVPN%4020190225/bVPN_2_5_1_setup.exe , I noticed that its service is hijackable due to the unquoted service path. Using this vulnerability, attackers can execute different files as waselvpnserv. It allows local users to replace the service with arbitrary code to escalate their privileges. I hope you check this link for more details: https://cwe.mitre.org/data/definitions/428.html

carolcoral commented 3 years ago

it still work