CVE-2025-43917
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Apr 19, 2025
Updated: Apr 21, 2025
CWE ID 863
Summary
CVE-2025-43917 is a vulnerability affecting the Pritunl Client before version 1.3.4220.57. It allows an administrator with access to the /Applications directory to escalate privileges after uninstalling the product. By inserting a new file at the pathname of the removed pritunl-service file, an attacker can exploit this vulnerability and have the file executed as root by a LaunchDaemon. This issue poses a significant risk to macOS systems with the Pritunl Client installed, and it is recommended that users upgrade to the latest version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Client