← Vulnerability feed

Vulnerability record · CVE-2022-24141 · published 6 July 2022

CVE-2022-24141: Iobit itop vpn vulnerability

Iobit · Itop Vpn

The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing ImpersonateNamedPipeClient().

5.4 CVSS 3.1 Medium EPSS 0.58% · top 54.4%
5.4CVSS 3.1 base score, v2 5.5
0.58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
9 Jul 2026Last modified by NVD

Description

The iTopVPNmini.exe component of iTop VPN 3.2 will try to connect to datastate_iTopVPN_Pipe_Server on a loop. An attacker that opened a named pipe with the same name can use it to gain the token of another user by listening for connections and abusing ImpersonateNamedPipeClient().

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/tomerpeled92/CVE/ Third Party Advisory
https://github.com/tomerpeled92/CVE/ Third Party Advisory

Track CVE-2022-24141 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2022-24141), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.