ExpressVPN before 12.73.0 on Windows, when split tunneling is used, sends DNS requests according to the Windows configuration (e.g., sends them to DNS servers operated by the user's ISP instead of to the ExpressVPN DNS servers), which may allow remote attackers to obtain sensitive information about websites visited by VPN users.
History

Wed, 30 Oct 2024 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-922
CPEs cpe:2.3:a:expressvpn:expressvpn:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Sep 2024 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Expressvpn
Expressvpn expressvpn
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:expressvpn:expressvpn:*:*:*:*:*:windows:*:*
Vendors & Products Expressvpn
Expressvpn expressvpn
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-30T19:12:30.970Z

Reserved: 2024-02-11T00:00:00

Link: CVE-2024-25728

cve-icon Vulnrichment

Updated: 2024-08-01T23:52:06.236Z

cve-icon NVD

Status : Modified

Published: 2024-02-11T22:15:08.360

Modified: 2024-11-21T09:01:17.043

Link: CVE-2024-25728

cve-icon Redhat

No data.