ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain sensitive information about websites visited by VPN users.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 30 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-922 | |
| CPEs | cpe:2.3:a:expressvpn:expressvpn:*:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Thu, 05 Sep 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Expressvpn
Expressvpn expressvpn |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:expressvpn:expressvpn:*:*:*:*:*:windows:*:* | |
| Vendors & Products |
Expressvpn
Expressvpn expressvpn |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-02-11T00:00:00
Updated: 2024-10-30T19:12:30.970Z
Reserved: 2024-02-11T00:00:00
Link: CVE-2024-25728
Updated: 2024-08-01T23:52:06.236Z
Status : Modified
Published: 2024-02-11T22:15:08.360
Modified: 2024-11-21T09:01:17.043
Link: CVE-2024-25728
No data.