Executive brief
Hotspot Shield, a popular VPN service used to secure internet connections and bypass regional content restrictions, contains a security flaw in its Windows service component. A local user on a shared computer could exploit this to gain full administrative control over the system. This could allow an attacker to bypass security software, access sensitive data, or disrupt the computer's operations.
Technical details
Hotspot Shield 6.0.3 contains an unquoted service path vulnerability (CWE-428) within the 'hshld' service binary (cmw_srv.exe). The service path is not enclosed in quotation marks, which allows a local attacker with low privileges to place a malicious executable in a parent directory of the service path (e.g., C:\Program.exe). Because the service runs with LocalSystem privileges, the malicious code will execute with elevated permissions upon the next service restart or system reboot. This vulnerability requires local access to the file system but no user interaction beyond the system restart. A proof-of-concept exploit is publicly available.
Affected products
- Hotspotshield Hotspot Shield 6.0.3
Timeline
- 2016-10-13: disclosed: Initial discovery and exploit published on Exploit-DB
- 2026-04-04: advisory: NVD/VulnCheck advisory published