Turbo VPN: Unquoted Search Path Vulnerability
Vulnerable Software: Turbo VPN
Affected Version: 1.1.0.0
Vendor Homepage: https://www.turbovpn.co/#/views/index
CVE: –
CVE Author: Tejas Nitin Pingulkar
Exploit Available: POC Available
About Affected Software:
Turbo VPN For PC is a free VPN client which offers free VPN proxy giving you the chance to unblock sites and applications and gain access to restricted resources.
Exploit:
Turbo VPN 1.1.0.0 installers and applications are vulnerable to unquoted search path vulnerability as application search path are not quoted that is when application search for binaries TurboVPN folder stored in “C:\Program files(x86)\TurboVPN” it uses below search order as path is not quoted
C:\Program.exe
C:\Program (x86)\TurboVPN
As on drive C:\ all users have full access, an attacker can place malicious exe with name “Program.exe” in C:\ path and wait for application to call Program.exe and escalate his/her privileges
Affected application: turbo VPN 1.1.0.0 windows version
POC
Thanks for sharing with us that awesome article you have amazing blog. Turbo VPN for PC
ReplyDeleteGood work with the hard work you have done I appreciate your work thanks for sharing it...
ReplyDeleteUSA VPN Free – VPN Proxy
I am very impressed with your post because this post is very beneficial for me and provide a new knowledge to me.
ReplyDeleteusa-vpn-free-vpn-proxy
avast-secure-browser
vsdc-video-editor
Thanks for sharing this information. I really like your blog post very much. You have really shared a informative and interesting blog post . why is kodi not connecting to network
ReplyDeleteNord vpn mod apk is the best VPN than any other VPN because of its premium features and ultra high speed performance.
ReplyDelete