Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Bitmask Riseup Local Privilege Escalation

High

Synopsis

Tenable has discovered a privilege escalation vulnerability in the Bitmask Riseup VPN 0.21.6 (the latest version on bitmask.net/en/install, marked as 0.21.2 there) as installed on Windows 10. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower privileged users to replace the VPN executable with a malicious one. When a higher privileged user such as an Administrator launches that executable, it is possible for the lower privileged user to escalate to Administrator privileges.

Solution

Use installation media for version 0.21.11 or later.

Disclosure Timeline

October 18, 2021 - Tenable discloses to vendor.
October 26, 2021 - Tenable requests acknowledgment of disclosure.
October 28, 2021 - Vendor acknowledges issue and requests further contact details.
November 1, 2021 - Tenable provides requested details.
November 3, 2021 - Vendor provides bug tracker access.
November 4, 2021 - Tenable confirms access.
December 10, 2021 - Vendor provides status update.
December 15, 2021 - Vendor provides status update.
December 17, 2021 - Vendor provides status update and notifies of fix.

All information within TRA advisories is provided “as is”, without warranty of any kind, including the implied warranties of merchantability and fitness for a particular purpose, and with no guarantee of completeness, accuracy, or timeliness. Individuals and organizations are responsible for assessing the impact of any actual or potential security vulnerability.

Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.

For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.

If you have questions or corrections about this advisory, please email [email protected]

Risk Information

CVE ID: CVE-2021-44466
Tenable Advisory ID: TRA-2021-58
Credit:
Nick Manfredi
CVSSv3 Base / Temporal Score:
7.0 / 6.6
CVSSv3 Vector:
AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products:
Bitmask Riseup 0.21.6
Risk Factor:
High

Advisory Timeline

December 30, 2021 - Initial release.