Viscosity
Vendor:
First CVE: Jan 10, 2020 · Active for 6 years
4
Total CVEs
More Total CVEs than 75% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Viscosity over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2020
6 years ago
Most Recent CVE
May 27, 2025
426 days ago
CVE Severity & Scoring
Viscosity4 CVEs
25%
50%
25%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (75.0%)
Network1 (25.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (75.0%)
Unknown0 (0.0%)
Required1 (25.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None2 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4284CRITICAL A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the setuid-set ViscosityHelper binary, which could let a remote ma | Jan 10, 2020 | 9.8 | 84 | NO | YES |
CVE-2017-20123HIGH A vulnerability was found in Viscosity 1.6.7. It has been classified as critical. This affects an unknown part of the component DLL Handler. The manipulation leads to untrusted sea | Jun 30, 2022 | 7.8 | 26 | NO | NO |
CVE-2020-5180HIGH Viscosity 1.8.2 on Windows and macOS allows an unprivileged user to set a subset of OpenVPN parameters, which can be used to load a malicious library into the memory of the OpenVPN | Jan 14, 2020 | 7.8 | 24 | NO | NO |
CVE-2025-4412MEDIUM On macOS systems, by utilizing a Launch Agent and loading the viscosity_openvpn process from the application bundle, it is possible to load a dynamic library with Viscosity's TCC ( | May 27, 2025 | 4.8 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
25.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
25.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Viscosity
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.8.2 | 1 | 7.8 | 0.4% | 0 | 0 |
| 1.6.7 | 1 | 7.8 | 1.2% | 0 | 0 |
| 1.4.1 | 1 | 9.8 | 69.5% | 0 | 1 |