OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
Metrics
Affected Vendors & Products
References
History
Sat, 10 Aug 2024 04:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | ||
Vendors & Products |
Openvpn openvpn2
|
|
Metrics |
ssvc
|
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: OpenVPN
Published: 2024-07-08T10:27:40.125Z
Updated: 2024-08-23T03:55:35.767Z
Reserved: 2024-03-12T18:26:01.705Z
Link: CVE-2024-27903
Vulnrichment
Updated: 2024-08-02T00:41:55.566Z
NVD
Status : Modified
Published: 2024-07-08T11:15:10.390
Modified: 2024-11-21T09:05:23.177
Link: CVE-2024-27903
Redhat
No data.