Description
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-9647 | OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges |
References
History
Tue, 29 Apr 2025 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Openvpn Openvpn openvpn |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows Openvpn Openvpn openvpn |
Fri, 04 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 03 Apr 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges | |
| Weaknesses | CWE-268 | |
| References |
|
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2025-04-04T13:25:17.430Z
Reserved: 2024-05-14T17:31:57.913Z
Link: CVE-2024-4877
Updated: 2025-04-04T13:24:06.558Z
Status : Analyzed
Published: 2025-04-03T16:15:32.840
Modified: 2025-04-29T19:45:07.223
Link: CVE-2024-4877
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD