Impact
A local authenticated Windows user can exploit the OpenVPN Windows Interactive Service to bypass the trusted configuration directory constraint and load arbitrary configuration files using specially crafted paths. This flaw, identified as a path traversal weakness, allows the attacker to place or modify configuration files that influence the OpenVPN client’s behavior, potentially redirecting traffic or granting unauthorized control over VPN connections. While the flaw does not grant remote code execution, it constitutes local configuration tampering that can jeopardize confidentiality, integrity, and availability of VPN sessions for the compromised system.
Affected Systems
OpenVPN OpenVPN versions 2.7_alpha1 through 2.7.6 running the Windows Interactive Service are affected. The vulnerability exists in the service component that handles configuration file loading on Windows installations.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity. Exploitation requires local authenticated access on a Windows machine, so it cannot be triggered remotely. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The risk is considered moderate with a limited attack surface, and applying the vendor’s fix mitigates the risk.
OpenCVE Enrichment