Vulnerability Description
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hola | Vpn | 1.34 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/101787Third Party AdvisoryVDB Entry
- https://www.vulnerability-lab.com/get_content.php?id=2062ExploitThird Party Advisory
- http://www.securityfocus.com/bid/101787Third Party AdvisoryVDB Entry
- https://www.vulnerability-lab.com/get_content.php?id=2062ExploitThird Party Advisory
FAQ
What is CVE-2017-16757?
CVE-2017-16757 is a vulnerability with a CVSS score of 7.8 (HIGH). Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.
How severe is CVE-2017-16757?
CVE-2017-16757 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16757?
Check the references section above for vendor advisories and patch information. Affected products include: Hola Vpn.