mullvad / mullvadvpn-app

The Mullvad VPN client app for desktop and mobile
https://mullvad.net/
GNU General Public License v3.0
5.13k stars 342 forks source link

Use absolute path for taskkill in installer (MLLVD-CR-24-06) #7225

Closed dlon closed 3 days ago

dlon commented 3 days ago

Fix a potential attack where users can cause the installer to run any executable called taskkill.exe in the working directory.

Fix DES-1502.


This change is Reviewable

linear[bot] commented 3 days ago

DES-1502 Fix windows installer running adjacent `taskkill.exe` (MLLVD-CR-24-06)