CVE-2025-43917: Pritunl Pritunl-Client

High severity, CVSS 8.2. EPSS: 0.2% chance of exploitation in the next 30 days.

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root.

Affected products

  • Pritunl Pritunl-Client: before 1.3.4220.57 (fixed in 1.3.4220.57)

Published 2025-04-19. Last modified 2026-06-17.