VYPR
Critical severity9.8NVD Advisory· Published Apr 16, 2018· Updated Jun 17, 2026

CVE-2018-10170

CVE-2018-10170

Description

NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Nordvpn/Nordvpn2 versions
    cpe:2.3:a:nordvpn:nordvpn:6.12.7.0:*:*:*:*:windows:*:*+ 1 more
    • cpe:2.3:a:nordvpn:nordvpn:6.12.7.0:*:*:*:*:windows:*:*
    • (no CPE)range: = 6.12.7.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.