CVE-2018-3952: Nordvpn
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafted configuration file can cause a privilege escalation, resulting in the execution of arbitrary commands with system privileges.
Affected products
- Nordvpn Nordvpn: version 6.14.28.0 only
Published 2018-09-07. Last modified 2026-06-17.