Turbo VPN: Unquoted Search Path Vulnerability

Vulnerable Software: Turbo VPN

Affected Version: 1.1.0.0

Vendor Homepage: https://www.turbovpn.co/#/views/index

CVE: –

CVE Author: Tejas Nitin Pingulkar

Exploit Available: POC Available

About Affected Software:

Turbo VPN For PC is a free VPN client which offers free VPN proxy giving you the chance to unblock sites and applications and gain access to restricted resources.

Exploit:

Turbo VPN 1.1.0.0 installers and applications are vulnerable to unquoted search path vulnerability as application search path are not quoted that is when application search for binaries TurboVPN folder stored in “C:\Program files(x86)\TurboVPN” it uses below search order as path is not quoted

C:\Program.exe
C:\Program (x86)\TurboVPN
As on drive C:\ all users have full access, an attacker can place malicious exe with name “Program.exe” in C:\ path and wait for application to call Program.exe and escalate his/her privileges

Affected application: turbo VPN 1.1.0.0 windows version

POC




Comments

  1. Thanks for sharing with us that awesome article you have amazing blog. Turbo VPN for PC

    ReplyDelete
  2. Good work with the hard work you have done I appreciate your work thanks for sharing it...
    USA VPN Free – VPN Proxy

    ReplyDelete
  3. I am very impressed with your post because this post is very beneficial for me and provide a new knowledge to me.
    usa-vpn-free-vpn-proxy
    avast-secure-browser
    vsdc-video-editor

    ReplyDelete
  4. Thanks for sharing this information. I really like your blog post very much. You have really shared a informative and interesting blog post . why is kodi not connecting to network

    ReplyDelete
  5. Nord vpn mod apk is the best VPN than any other VPN because of its premium features and ultra high speed performance.

    ReplyDelete

Post a Comment

Popular posts from this blog

CVE-2020-23446 Verint Workforce Optimization (WFO)

CVE-2020-13474: NCH Express Accounts- Privilege Escalation

CVE-2020-13475: NCH accounts-Cross Site Scripting