Impact
The vulnerability allows a locally authenticated user on a Windows system to force the OpenVPN Windows interactive service to load configuration files from outside the trusted directory. By crafting options that bypass the service’s whitelist checks, an attacker can read or modify arbitrary VPN configuration files. This could alter routing, protocol settings, or certificates used by the VPN, potentially redirecting traffic or enabling data exfiltration. The flaw is classified as a path traversal (CWE-183 and CWE-22) that permits local file manipulation.
Affected Systems
OpenVPN versions 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 running on Windows. The interactive service component is the only one affected; other OpenVPN components are not cited as vulnerable. No specific hardware or OS version constraints beyond the Windows platform requirement were identified.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, while the EPSS score of less than 1% reflects a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local, authenticated access to a Windows machine where the OpenVPN service is running and the ability to craft custom configuration options. The impact is confined to the local machine, though it could propagate to endpoints using the modified VPN configuration.
OpenCVE Enrichment