{"id":"CVE-2025-65199","summary":"Windscribe for Linux 'changeMTU' local privilege escalation","details":"A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.","modified":"2026-08-12T03:51:47.036933950Z","published":"2025-12-10T18:04:35.733Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.10.1"},{"fixed":"2.18.3-alpha"}]}],"cna_assigner":"cisa-cg","cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65199.json"},"references":[{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2025-65199"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/65xxx/CVE-2025-65199.json"},{"type":"ADVISORY","url":"https://hackingbydoing.wixsite.com/hackingbydoing/post/windscribe-vpn-local-privilege-escalation"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-65199"},{"type":"ADVISORY","url":"https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-343-01.json"},{"type":"FIX","url":"https://github.com/Windscribe/Desktop-App/compare/v2.18.2...v2.18.3?diff=unified&w#diff-57e27ab201a1a612609087b839e03bf87a5a063ffcc3f465a6245469bc102754"},{"type":"FIX","url":"https://github.com/Windscribe/Desktop-App/compare/v2.18.2...v2.18.3?diff=unified&w#diff-cfc5df17057ed92112ae70a42c81c57c79f434429210ff881fb0771cf8e39b4c"},{"type":"PACKAGE","url":"https://github.com/Windscribe/Desktop-App"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/windscribe/desktop-app","events":[{"introduced":"0"},{"fixed":"7a7cf5f073defb7002a71f1032052b9e2f2f5939"}],"database_specific":{"extracted_events":[{"introduced":"2.10.1"},{"fixed":"2.18.8"}],"source":"AFFECTED_FIELD"}}],"versions":["2.18.3","2.18.5","v2.18.5","v2.18.3","v2.18.2","v2.17.9","v2.18.1","v2.17.7","v2.17.6","v2.17.5","v2.17.4","v2.17.3","v2.17.2","v2.17.1","v2.16.14","v2.16.11","v2.16.8","v2.16.7","v2.16.6","v2.16.5","v2.16.4","v2.16.3","v2.16.2","v2.15.8","v2.15.7","v2.15.6","v2.15.5","v2.15.4","v2.15.3","v2.14.12","v2.14.10","v2.14.9","v2.14.8","v2.14.7","v2.14.6","v2.14.5","v2.14.4","v2.14.3","v2.13.8","v2.13.7","v2.13.6","v2.13.5","v2.13.4","v2.13.3","v2.13.2","v2.12.7","v2.12.4","v2.12.3","v2.12.2","v2.12.1","v2.11.11","v2.11.9","v2.11.8","v2.11.7","v2.11.6","v2.11.5","v2.10.15","v2.11.4","v2.10.14","v2.10.12","v2.10.11","v2.10.10","v2.10.9","v2.10.8","v2.10.7","v2.10.6","v2.10.5","v2.10.4","v2.9.9","v2.9.7","v2.9.6","v2.9.5","v2.9.4","v2.8.6","v2.8.5","v2.8.4","v2.8.3","v2.8.2","v2.8.1","v2.7.14","v2.4.1","v2.3.15"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-65199.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}