Vulnerabilities > Aviatrix > VPN Client > High

DATE CVE VULNERABILITY TITLE RISK
2021-04-29 CVE-2021-31776 Unquoted Search Path or Element vulnerability in Aviatrix VPN Client
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.
local
low complexity
aviatrix CWE-428
7.8
2019-12-05 CVE-2019-17388 Incorrect Permission Assignment for Critical Resource vulnerability in Aviatrix VPN Client
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
local
low complexity
aviatrix CWE-732
7.8
2019-12-05 CVE-2019-17387 Unspecified vulnerability in Aviatrix VPN Client
An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS.
local
low complexity
aviatrix
7.8