Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nord VPN 6.31.13.0 contains an unquoted service path vulnerability in its nordvpn-service that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted binary path during system startup or reboot to potentially run malicious code with LocalSystem permissions. | |
| Title | Nord VPN-6.31.13.0 - 'nordvpn-service' Unquoted Service Path | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-01-28T14:33:26.269Z
Reserved: 2026-01-27T15:47:08.000Z
Link: CVE-2020-36992
Updated: 2026-01-28T14:33:11.812Z
Status : Received
Published: 2026-01-28T13:15:52.490
Modified: 2026-01-28T13:15:52.490
Link: CVE-2020-36992
No data.
OpenCVE Enrichment
No data.