CVE-2020-25744
SaferVPN vulnerability analysis and mitigation

Overview

SaferVPN for Windows before version 5.0.3.3 contained a vulnerability that allowed low-privileged users to create or overwrite arbitrary files, potentially leading to a denial of service (DoS) condition. The vulnerability, tracked as CVE-2020-25744, was discovered on September 8, 2020, and was silently fixed by the vendor on September 16, 2020 (Medium Blog).

Technical details

The vulnerability stems from improper file access control in SaferVPN's logging mechanism. The application spawns openvpn.exe with SYSTEM privileges, which creates log files named xxx_ovpn.log under %USERPROFILE%\AppData\Local\SaferVPN\Log. Due to users having full control over the log folder, they could delete existing files and create symbolic links pointing to privileged system files. When openvpn.exe attempts to write logs, it follows these symbolic links, potentially overwriting critical system files (Medium Blog). The vulnerability has a CVSS v3.1 base score of 8.1 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H) (NVD).

Impact

The primary impact of this vulnerability is the potential for denial of service through arbitrary file overwrites. While an attacker has limited control over the content being written, they can target critical system files, potentially disrupting system operations. The vulnerability requires local user access to exploit (Medium Blog).

Exploitability

The vulnerability can be exploited by deleting files under the SaferVPN log folder and creating a symbolic link pointing to a privileged file (e.g., C:\Windows\win.ini). When a user connects to the VPN, the openvpn.exe process follows the symbolic link and overwrites the target file with log contents. A proof-of-concept exploit has been publicly demonstrated (Medium Blog).

Mitigation and workarounds

The vulnerability was fixed in SaferVPN version 5.0.3.3. The fix involves relocating the log folder to C:\ProgramData\Mudhook Marketing, Inc\SaferVPN\Diagnostics\Service with proper permissions and eliminating the creation of country-specific log files. Users should upgrade to version 5.0.3.3 or later to mitigate this vulnerability (Medium Blog).

Additional resources


SourceThis report was generated using AI

Related SaferVPN vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-25744HIGH8.1
  • SaferVPN logoSaferVPN
  • cpe:2.3:a:safervpn:safervpn
NoYesSep 18, 2020
CVE-2020-26050HIGH7.8
  • SaferVPN logoSaferVPN
  • cpe:2.3:a:safervpn:safervpn
NoNoJan 12, 2021
CVE-2018-10647HIGH7.8
  • SaferVPN logoSaferVPN
  • cpe:2.3:a:safervpn:safervpn
NoNoMay 02, 2018

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management