ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain sensitive information about websites visited by VPN users.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-922 | |
CPEs | cpe:2.3:a:expressvpn:expressvpn:*:*:*:*:*:*:*:* | |
Metrics |
ssvc
|
Thu, 05 Sep 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Expressvpn
Expressvpn expressvpn |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:expressvpn:expressvpn:*:*:*:*:*:windows:*:* | |
Vendors & Products |
Expressvpn
Expressvpn expressvpn |
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-30T19:12:30.970Z
Reserved: 2024-02-11T00:00:00
Link: CVE-2024-25728

Updated: 2024-08-01T23:52:06.236Z

Status : Modified
Published: 2024-02-11T22:15:08.360
Modified: 2024-11-21T09:01:17.043
Link: CVE-2024-25728

No data.