Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Windscribe

First CVE: May 23, 2018Active for: 8 yearsTotal CVEs: 7

Windscribe is a VPN and privacy service whose vulnerability profile centers on a single client application and recurs through weakness classes including improper input validation, path traversal, OS command injection, improper privilege management, and incorrect permission assignment for critical resources—issues endemic to the access-control and system-interaction demands of a locally executing privacy tool. The durable signal is that disclosures for this vendor tend to acquire public exploit code, reflecting the security-research appeal of a widely installed client with privileged system access. Current exploitation, severity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
1.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Windscribe over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 23, 2018
8 years ago
Most Recent CVE
Dec 10, 2025
227 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-11479HIGH
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService
May 25, 20187.848NOYES
CVE-2022-41141HIGH
This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability to execute low-privileged code o
Jan 26, 20237.826NONO
CVE-2020-27518HIGH
All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could lev
May 4, 20217.826NONO
CVE-2025-65199HIGH
A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root
Dec 10, 20257.825NONO
CVE-2020-22809HIGH
In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation.
May 10, 20217.824NONO
CVE-2018-11334HIGH
Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipe\WindscribeService.
May 23, 20187.823NONO
CVE-2024-6141HIGH
Windscribe Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. A
Aug 21, 20247.822NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
100%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
High
Attack Vector
Local7 (100.0%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
14.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
14.3% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Windscribe.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Windscribe — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Windscribe's Products

View all 3 CNAs →

Top CWEs