cbcvebase.

Sparklabs Viscosity vulnerabilities

4 known vulnerabilities affecting sparklabs/viscosity.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2012-4284P2CRITICALCVSS 9.8PoCv1.4.12020-01-10
CVE-2012-4284 [CRITICAL] CVE-2012-4284: A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name valida A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote malicious user execute arbitrary code
nvd
CVE-2020-5180P3HIGHCVSS 7.8v1.8.22020-01-14
CVE-2020-5180 [HIGH] CVE-2020-5180: Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN paramete Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN process, leading to limited local privilege escalation. (When a VPN connection is initiated using a TLS/SSL client profile, the privileges are dropped, and the library will be loaded
nvd
CVE-2017-20123P3HIGHCVSS 7.8v1.6.72022-06-30
CVE-2017-20123 [HIGH] CWE-426 CVE-2017-20123: A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an un A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted search path. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.6.8 is able to address this is
nvd
CVE-2025-4412P4MEDIUMCVSS 4.8≤ 1.11.42025-05-27
CVE-2025-4412 [MEDIUM] CWE-276 CVE-2025-4412: On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the app On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC (Transparency, Consent, and Control) identity. The acquired resource access is limited without entitlements such as access to the camera or microphone. Only user-granted perm
nvd
Sparklabs Viscosity vulnerabilities | cvebase