Windscribe records
7 published records for vendor windscribe.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 14.3%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-269 Improper Privilege Management1
- CWE-427 Uncontrolled Search Path Element1
- CWE-428 Unquoted Search Path or Element1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
34Monitor | CVE-2018-11479Weaponized | The VPN component in Windscribe 1.81 uses the OpenVPN client for connections.windscribe · windscribe · CWE-20 | High7.8 | — | 9.9% | May 25, 2018 |
31Monitor | CVE-2024-6141No exploit | Windscribe Directory Traversal Local Privilege Escalation Vulnerabilitywindscribe · windscribe · CWE-22 | High7.8 | — | 0.6% | Aug 21, 2024 |
31Monitor | CVE-2020-27518No exploit | All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService cwindscribe · windscribe · CWE-269 | High7.8 | — | 0.4% | May 4, 2021 |
31Monitor | CVE-2020-22809No exploit | In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.windscribe · windscribe · CWE-428 | High7.8 | — | 0.4% | May 10, 2021 |
31Monitor | CVE-2022-41141No exploit | This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe.windscribe · windscribe · CWE-427 | High7.8 | — | 0.4% | Jan 26, 2023 |
31Monitor | CVE-2018-11334No exploit | Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipwindscribe · windscribe · CWE-732 | High7.8 | — | 0.3% | May 23, 2018 |
29Monitor | CVE-2025-65199No exploit | Windscribe for Linux 'changeMTU' local privilege escalationwindscribe · windscribe · CWE-78 | High7.3 | — | 1.3% | Dec 10, 2025 |
- CVE-2018-1147934Monitor
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections.
HighCVSS 7.8WeaponizedEPSS 10%windscribe · windscribeMay 25, 2018
- CVE-2024-614131Monitor
Windscribe Directory Traversal Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 1%windscribe · windscribeAug 21, 2024
- CVE-2020-2751831Monitor
All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService c
HighCVSS 7.8No exploitEPSS 0%windscribe · windscribeMay 4, 2021
- CVE-2020-2280931Monitor
In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
HighCVSS 7.8No exploitEPSS 0%windscribe · windscribeMay 10, 2021
- CVE-2022-4114131Monitor
This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe.
HighCVSS 7.8No exploitEPSS 0%windscribe · windscribeJan 26, 2023
- CVE-2018-1133431Monitor
Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pip
HighCVSS 7.8No exploitEPSS 0%windscribe · windscribeMay 23, 2018
- CVE-2025-6519929Monitor
Windscribe for Linux 'changeMTU' local privilege escalation
HighCVSS 7.3No exploitEPSS 1%windscribe · windscribeDec 10, 2025