← Vulnerability feed

Vulnerability record · CVE-2018-11479 · published 25 May 2018

CVE-2018-11479: Windscribe improper input validation vulnerability

Windscribe · Windscribe

The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.). There is no validation of the program name before constructing the lpCommandLine argument for a CreateProcess call. An attacker can run any malicious process with SYSTEM privileges through this named pipe.

7.8 CVSS 3.0 High EPSS 9.9% · top 4.6% CWE-20 · Improper input validation
7.8CVSS 3.0 base score, v2 7.2
9.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.). There is no validation of the program name before constructing the lpCommandLine argument for a CreateProcess call. An attacker can run any malicious process with SYSTEM privileges through this named pipe.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-11479 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-6141Windscribe path traversal vulnerabilityWindscribe Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected…EPSS 0.59%7.8CVE-2022-41141Windscribe uncontrolled search path element vulnerabilityThis vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability t…EPSS 0.37%7.8CVE-2020-22809Windscribe unquoted search path vulnerabilityIn Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.EPSS 0.40%7.8CVE-2020-27518Windscribe improper privilege management vulnerabilityAll versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component.…EPSS 0.44%7.8CVE-2018-11334Windscribe incorrect permission assignment vulnerabilityWindscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipe\Windscr…EPSS 0.33%7.3CVE-2025-65199Windscribe os command injection vulnerabilityA command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to exec…EPSS 1.3%9.5CVE-2026-88771Citrix netscaler application delivery controller improper input validation vulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2018-11479), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.