vendor:
NordVPN
by:
chipo
8.8
CVSS
HIGH
Unquoted Service Path
426
CWE
Product Name: NordVPN
Affected Version From: 6.31.13.0
Affected Version To: 6.31.13.0
Patch Exists: YES
Related CWE: N/A
CPE: a:nordvpn:nordvpn:6.31.13.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Pro x64 es
2020
Nord VPN-6.31.13.0 – ‘nordvpn-service’ Unquoted Service Path
A successful attempt to exploit this vulnerability could allow to execute code during startup or reboot with the elevated privileges.
Mitigation:
The vendor should ensure that all services are installed with an absolute path with quotes.