A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client for Windows allows a local attacker to escalate their privileges to NT AUTHORITY\SYSTEM on the machine where the client is installed. This issue affects the Mobile VPN with SSL client for Windows up to and including 2026.2.
📦
mobile_vpn_with_ssl
Vendor: watchguard
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
1
Remote Access
Total CVEs
3
Total Indexed
Avg. EPSS
1.50%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.3
CVSS
Severity: HIGH
7.8
CVSS
CVE-2024-4944
RCE
A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.
Severity: HIGH
7.6
CVSS
CVE-2024-3661
Exploit Found
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
Severity: HIGH