CVE-2024-45750: Thegreenbow Android VPN

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in TheGreenBow Windows Standard VPN Client 6.87.108 (and older), Windows Enterprise VPN Client 6.87.109 (and older), Windows Enterprise VPN Client 7.5.007 (and older), Android VPN Client 6.4.5 (and older) VPN Client Linux 3.4 (and older), VPN Client MacOS 2.4.10 (and older) allows a remote attacker to execute arbitrary code via the IKEv2 Authentication phase, it accepts malformed ECDSA signatures and establishes the tunnel.

Affected products

  • Thegreenbow Android VPN: up to and including 6.4.5
  • Thegreenbow VPN Client Linux: up to and including 3.4
  • Thegreenbow VPN Client macOS: up to and including 2.4.10
  • Thegreenbow Windows Enterprise VPN: up to and including 7.5.007
  • Thegreenbow Windows Standard VPN: up to and including 6.87.108

Published 2024-09-25. Last modified 2026-06-17.