← Vulnerability feed

Vulnerability record · CVE-2022-41141 · published 26 January 2023

CVE-2022-41141: Windscribe uncontrolled search path element vulnerability

Windscribe · Windscribe

This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-16859.

7.8 CVSS 3.1 High EPSS 0.37% · top 71.3% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The product loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-16859.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://windscribe.com/changelog/windows Release NotesVendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-22-1300/ Third Party AdvisoryVDB Entry
https://windscribe.com/changelog/windows Release NotesVendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-22-1300/ Third Party AdvisoryVDB Entry

Track CVE-2022-41141 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2024-6141Windscribe path traversal vulnerabilityWindscribe Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected…EPSS 0.59%7.8CVE-2020-22809Windscribe unquoted search path vulnerabilityIn Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.EPSS 0.40%7.8CVE-2020-27518Windscribe improper privilege management vulnerabilityAll versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component.…EPSS 0.44%7.8CVE-2018-11479Windscribe improper input validation vulnerabilityThe VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishe…EPSS 9.9%7.8CVE-2018-11334Windscribe incorrect permission assignment vulnerabilityWindscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipe\Windscr…EPSS 0.33%7.3CVE-2025-65199Windscribe os command injection vulnerabilityA command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to exec…EPSS 1.3%7.8CVE-2020-3433Cisco AnyConnect Windows client DLL hijacking via IPC channelCisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through …KEVEPSS 10%analysed6.5CVE-2020-3153Cisco AnyConnect Windows Installer Path Handling Privilege EscalationThe Cisco AnyConnect Secure Mobility Client for Windows installer mishandles directory paths, letting an authenticated local user copy attacker-suppl…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2022-41141), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.