[local] ProtonVPN v4.4.1 - Unquoted Service Path

未分配CVE

漏洞

High · CVSS N/A

📋 漏洞基础信息

CVE未分配CVE
漏洞类型漏洞
受影响版本详见原文
危害等级High · CVSS N/A
发布日期2026-07-07
提交者Milad Karimi
来源Exploit-DB 原文 ↗

⚔️ 原始 PoC

# Exploit Author: Milad Karimi
# Contact: karimimilad1337@gmail.com
# Zone-H: www.zone-h.org/archive/notifier=Ex3ptionaL


Description:
A successful attempt would require the local user to be able to insert
their code in the system root path undetected by the OS or other security
applications where it could potentially be executed during application
startup or reboot. If successful,
the local user's code would execute with
the elevated privileges of the application.

Proof Of Concept:
PS C:\Users\Emre>
sc.exe qc "ProtonVPN Wireguard"
[SC] QueryServiceConfig SUCCESS

SERVICE_NAME: ProtonVPN Wireguard
        TYPE : 10 WIN32_OWN_PROCESS
        START_TYPE : 3 DEMAND_START
        ERROR_CONTROL : 1 NORMAL
        BINARY_PATH_NAME : C:\Program Files (x86)\Proton
Technologies\ProtonVPN\ProtonVPN.WireGuardService.exe
C:\ProgramData\ProtonVPN\WireGuard\ProtonVPN.conf
        LOAD_ORDER_GROUP :
        TAG : 0
        DISPLAY_NAME : ProtonVPN WireGuard
        DEPENDENCIES : Nsi
                           : TcpIp
        SERVICE_START_NAME : LocalSystem

🛡️ 修复建议

请升级到厂商最新安全版本。

📎 参考链接

🚨 威胁评估

📈 EPSS 利用概率暂无数据
🚨 CISA KEV未被已知利用
🔧 公开 PoC暂无公开 PoC

⚠️ 本文基于公开漏洞数据库,仅供安全研究与防御参考。生成时间: 2026-08-03 08:36 | 来源: Exploit-DB

[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)