NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NextVPN 4.10 contains an insecure file permissions vulnerability that allows local users to modify executable files with full access rights. Attackers can replace system executables with malicious files to gain SYSTEM or Administrator privileges through unauthorized file modification. | |
| Title | NextVPN 4.10 - Insecure File Permissions | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-12T19:55:30.153Z
Reserved: 2026-02-12T18:28:05.299Z
Link: CVE-2019-25343
Updated: 2026-02-12T19:54:59.019Z
Status : Received
Published: 2026-02-12T20:16:00.010
Modified: 2026-02-12T20:16:00.010
Link: CVE-2019-25343
No data.
OpenCVE Enrichment
No data.