CVE-2024-27903Unverified Ownership in Openvpn

Severity
9.8CRITICALNVD
EPSS
7.0%
top 8.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 8
Latest updateMar 13

Description

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

NVDopenvpn/openvpn2.6.02.6.10+1
CVEListV5openvpn/openvpn_22.6.9 and earlier

🔴Vulnerability Details

1
GHSA
GHSA-63q4-8wcf-wg8f: OpenVPN plug-ins on Windows with OpenVPN 22024-07-08

📋Vendor Advisories

2
CISA ICS
Siemens SINEMA Remote Connect Client2025-03-13
Debian
CVE-2024-27903: openvpn - OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from ...2024

🕵️Threat Intelligence

1
Microsoft
Chained for attack: OpenVPN vulnerabilities discovered leading to RCE and LPE2024-08-08