High severity7.8NVD Advisory· Published Apr 29, 2021· Updated Jun 17, 2026
CVE-2021-31776
CVE-2021-31776
Description
Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:aviatrix:vpn_client:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:aviatrix:vpn_client:*:*:*:*:*:*:*:*range: <2.14.14
- (no CPE)range: <2.14.14
- Aviatrix/VPN Clientdescription
Patches
Vulnerability mechanics
References
3- docs.aviatrix.com/Downloads/samlclient.htmlnvdProductVendor Advisory
- docs.aviatrix.com/Downloads/samlclient.htmlnvdProductVendor Advisory
- docs.aviatrix.com/HowTos/changelog.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.