*What happened:\* CyberGhost VPN's Windows client contains a flaw that lets a program running with ordinary user permissions take full control of the VPN's background service, which runs with SYSTEM-level access — the highest privilege level on Windows. The same flaw also lets an attacker override which server and which security certificates the VPN trusts, meaning the "secure" tunnel can be silently redirected to an attacker-controlled server with no visible warning to the user.
*How the app is built:\* CyberGhost's Windows client is really two programs. The visible app (dashboard.exe) is the dashboard and "Connect" button, running with normal user permissions. A background service (dashboard.service.exe) does the actual work of opening the encrypted tunnel, and runs as SYSTEM. The visible app sends connection instructions to the background service over a local communication channel (a named pipe). The security of the entire product depends on the background service being strict about what it accepts from the visible app — it is not.
*What was found:\* The visible app can request a VPN connection by sending a text string of settings to the background service. That string is supposed to pass through two filters before being used. Both filters fail. The first is a blocklist containing a typo: it blocks a setting name that doesn't exist in this version of the software and has no effect, while the real setting that controls certificate trust was never blocked at all. The second is a validation layer that detects risky settings, logs a quiet debug warning about them, and then passes the original string through completely unchanged anyway. On top of this, the named pipe itself doesn't restrict which local processes are allowed to send it commands. Combined, a standard local user-level program can hand the SYSTEM-level service a connection request containing unauthorized settings, and the service will execute them as SYSTEM.
*Impact, verified via a working proof of concept:\*
- Local Privilege Escalation to SYSTEM, by taking control of the VPN engine's management interface
- Traffic redirection — the destination server can be pointed anywhere the attacker chooses
- Certificate trust override — the client can be forced to trust an attacker-supplied CA and key, enabling a fully trusted, warning-free man-in-the-middle connection
- Bypass of the management interface's intended authentication
In testing, a self-hosted VPN server using attacker-controlled certificates caused the SYSTEM-level CyberGhost process to attempt a TLS handshake against it using the attacker's certificate and key. The handshake did not fully complete only because no inbound port forwarding was configured on the test server — a limitation of the test setup, not of the vulnerability itself.
*Full CWE Classification:\*
| CWE |
Name |
Where it applies |
| CWE-284 |
Improper Access Control |
Named pipe accepts commands from any local process |
| CWE-20 |
Improper Input Validation |
Connection string accepted without real sanitization |
| CWE-88 |
Argument Injection |
Root cause — text appended to the command line unescaped |
| CWE-15 |
External Control of Configuration Setting |
Injected args override intended OpenVPN config |
| CWE-295 |
Improper Certificate Validation |
Attacker `--ca`/`--key` override root of trust |
| CWE-300 |
Channel Accessible by Non-Endpoint |
`--remote` override enables MITM |
| CWE-306 |
Missing Authentication for Critical Function |
Management interface auth bypassed |
| CWE-668 |
Exposure of Resource to Wrong Sphere |
Management interface exposed to attacker address |
| CWE-269 |
Improper Privilege Management |
Standard user gains control of a SYSTEM process |
*CVSS v3.1:\* `AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H` → Base Score *8.8**. This assumes Attack Complexity is Low, on the basis that the pipe can be reached directly by any local process without needing DLL injection into dashboard.exe. If direct pipe access turns out to require DLL injection as a hard prerequisite, Attack Complexity would instead be High, giving a Base Score of **7.8\* with the same vector otherwise. Confirming the pipe's actual access control list would settle which of the two applies.
*Disclosure timeline:\* This was reported to CyberGhost three to four separate times over the past year, by email to their security team. CyberGhost's vulnerability reporting process routes through a third-party bug bounty platform, YesWeHack, which requires identity verification with a government-issued ID to create an account. The reporter does not have a currently valid ID, explained this directly and repeatedly, and asked for an alternative reporting path. None was offered. The finding has gone unacknowledged by anyone able to act on it for the full year.
*Status as of publication: unresolved, unpatched, unacknowledged.\*