CVE-2024-37391: Proton Protonvpn
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive') + '"' in Setup/setup.iss.
Affected products
- Proton Protonvpn: before 3.2.10 (fixed in 3.2.10)
Published 2024-07-22. Last modified 2026-06-17.