vendor:
HMA Pro VPN Client
by:
Securify
7,2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: HMA Pro VPN Client
Affected Version From: 2.2.7.0
Affected Version To: 2.2.7.0
Patch Exists: NO
Related CWE: N/A
CPE: a:hidemyass:hma_pro_vpn_client:2.2.7.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OS X
2017
Multiple Local Privilege Escalation Vulnerabilities in HideMyAss Pro VPN Client v2.x for OS X
Multiple local privilege escalation vulnerabilities were found in the helper binary HMAHelper that ships with HideMyAss Pro VPN for OS X. The helper is installed setuid root and responsible for loading Kernel Extensions (kext) and managing VPN firewall rules. These issues can be leveraged by a local attacker to gain elevated (root) privileges.
Mitigation:
Users should uninstall the vulnerable version of HMA Pro VPN for OS X and switch to a different VPN service.