Vulnerability Description
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-43917?
CVE-2025-43917 is a vulnerability with a CVSS score of 8.2 (HIGH). In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the ...
How severe is CVE-2025-43917?
CVE-2025-43917 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-43917?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.