CVE-2020-27518: Windscribe

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could leverage several openvpn options to execute code as root/SYSTEM.

Affected products

  • Windscribe Windscribe: up to and including 2.02.10

Published 2021-05-04. Last modified 2026-07-09.