VendorsSparkLabsviscosityall versions
Vulnerabilities

SparkLabs Viscosity

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2012-4284
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code
Published 2020-01-10 · Modified
10.02 PoCEPSS 0.695
CVE-2017-20123
Viscosity DLL untrusted search path
Published 2022-06-30 · Modified
8.8EPSS 0.013
CVE-2020-5180
Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN process, leading to limited local privilege escalation. (When a VPN connection is initiated using a TLS/SSL client profile, the privileges are dropped, and the library will be loaded, resulting in arbitrary code execution as a user with limited privileges. This greatly reduces the impact of the vulnerability.)
Published 2020-01-14 · Modified
7.8EPSS 0.004