Windscribe is a VPN and privacy service whose vulnerability profile centers on a single client application and recurs through weakness classes including improper input validation, path traversal, OS command injection, improper privilege management, and incorrect permission assignment for critical resources—issues endemic to the access-control and system-interaction demands of a locally executing privacy tool. The durable signal is that disclosures for this vendor tend to acquire public exploit code, reflecting the security-research appeal of a widely installed client with privileged system access. Current exploitation, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Windscribe over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-11479HIGH The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService | May 25, 2018 | 7.8 | 48 | NO | YES |
CVE-2022-41141HIGH This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. An attacker must first obtain the ability to execute low-privileged code o | Jan 26, 2023 | 7.8 | 26 | NO | NO |
CVE-2020-27518HIGH All versions of Windscribe VPN for Mac and Windows <= v2.02.10 contain a local privilege escalation vulnerability in the WindscribeService component. A low privilege user could lev | May 4, 2021 | 7.8 | 26 | NO | NO |
CVE-2025-65199HIGH A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root | Dec 10, 2025 | 7.8 | 25 | NO | NO |
CVE-2020-22809HIGH In Windscribe v1.83 Build 20, 'WindscribeService' has an Unquoted Service Path that facilitates privilege escalation. | May 10, 2021 | 7.8 | 24 | NO | NO |
CVE-2018-11334HIGH Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipe\WindscribeService. | May 23, 2018 | 7.8 | 23 | NO | NO |
CVE-2024-6141HIGH Windscribe Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Windscribe. A | Aug 21, 2024 | 7.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Windscribe.
Media articles that mention a CVE ID that affects a product developed by Windscribe — matched by CVE ID, not by vendor name.