Vulnerabilities > Hola > VPN > 1.34

DATE CVE VULNERABILITY TITLE RISK
2017-11-09 CVE-2017-16757 Incorrect Permission Assignment for Critical Resource vulnerability in Hola VPN 1.34
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.
local
low complexity
hola CWE-732
4.6