CVE-2017-16757: Hola VPN
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.
Affected products
- Hola VPN: version 1.34 only
Published 2017-11-09. Last modified 2026-06-17.