Back

CVE-2018-10169

CRITICAL

ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "ProtonVPN Service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection. This plugin will execute code in the context of the SYSTEM user.

Published: Apr 16, 2018 Modified: Jun 17, 2026
CWE-732

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
protonmail protonvpn 1.3.3

GitHub Security Advisory GHSA-ph8h-hf9v-jm2r

ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the ...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 2.54%

Top 16% most likely to be exploited

Threat Score 40 / 100

Data Sources

NVD EPSS GitHub