Security flaws found in top VPNs

VPN
VPN-tjänster har många olika funktioner - här är de allra viktigaste du ska kolla efter. (Image credit: Shutterstock.com)

Security flaws have been uncovered in some of the most popular VPN services on the market today.

Researchers at Cisco Talos discovered two vulnerabilities in the NordVPN and ProtonVPN offerings that could have allowed hackers to hijack a user's machine.

The flaws took advantage of a design issue in both clients, with the creation of a new OpenVPN command line possibly allowing attackers to carry out the execution of abritary code on Windows machines without needing authorisation, putting user's machines at risk.

VPN security

The flaws, which were named CVE-2018-3952 and CVE-2018-4010, were similar to one found earlier this year by VerSprite, which had then been patched by both vendors, however the Talos team were able to circumvent these fixes.

The fixes were initially released in April, with NordVPN issuing a second patch last month, meaning the majority of their users were automatically protected.

"We have a diligent team of dedicated software engineers and cybersecurity experts working on our system to keep it as secure and functional as possible," NordVPN's Daniel Markuson wrote in a company blog

"With that being said, everyone makes mistakes. That’s why the work of institutions like Talos Intelligence is so important. By discovering vulnerabilities and reporting them to companies before they’re published, they help make the internet a more secure place for everyone – without endangering users in the process."

ProtonVPN released their patch version earlier this month. 

"Later versions of ProtonVPN have resolved this issue and users have been automatically prompted to update," a ProtonVPN spokesperson told ZDNet. "We have not seen any evidence of this being exploited in the wild, as a user's computer needs to first be compromised by a hacker before this bug can be exploited."

The Talos team advised all ProtonVPN and NordVPN users to patch their VPNs as soon as possible to avoid any potential risk.

VIA: ZDNet

TOPICS
Mike Moore
Deputy Editor, TechRadar Pro

Mike Moore is Deputy Editor at TechRadar Pro. He has worked as a B2B and B2C tech journalist for nearly a decade, including at one of the UK's leading national newspapers and fellow Future title ITProPortal, and when he's not keeping track of all the latest enterprise and workplace trends, can most likely be found watching, following or taking part in some kind of sport.

Latest in VPN Privacy & Security
Neon blue email symbols on a black background
Why am I suddenly getting so many spam emails?
A computer file surrounded by red laser beams
Cover your tracks: the risk of sending unencrypted files
Using an Amazon Fire Stick on a Smart TV
How to use a VPN with Fire Stick
Close up of PS5 DualSense controller leaning on a PS5
5 reasons your PS5 needs a VPN
Tor
What is Onion over VPN?
 In this photo illustration a Google Play logo seen displayed on a smartphone.
Why is there so much spyware hidden in the Play Store?
Latest in News
Stability AI 3D Video
Stability AI’s new virtual camera turns any image into a cool 3D video and I’m blown away by how good it is
The Google Wallet app with a mode for kids shown on-screen.
Google Wallet’s new kid-friendly payment system is a win for parents
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
Vertere DG-X turntable on a pink/white TechRadar background
Vertere's elite DG X turntable is modular, expensive, and hugely desirable
Google Pixel 9a
Google is delaying the Pixel 9a to fix a mystery “component quality issue”
The bottom left corner of an Android phone, showing the Phone, Messages, Google icons and Google Search bar
Google Messages remote delete will soon save you from texting embarrassment – and here's how it works