Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 04 Jul 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications. | |
| Weaknesses | CWE-459 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-07-04T00:00:00.000Z
Updated: 2025-07-08T14:36:02.112Z
Reserved: 2025-04-17T00:00:00.000Z
Link: CVE-2025-43711
Updated: 2025-07-08T14:35:04.935Z
Status : Awaiting Analysis
Published: 2025-07-05T00:15:23.733
Modified: 2025-07-08T16:18:53.607
Link: CVE-2025-43711
No data.