Impact
An argument parsing flaw in OpenVPN permits a remote authenticated user to embed malicious command strings within the certificate subject field. The vulnerability enables the attacker to execute arbitrary commands on the Windows server process that runs OpenVPN, potentially achieving full system compromise. The weakness is a classic command‑injection flaw (CWE‑78) coupled with improper certificate subject handling (CWE‑88).
Affected Systems
The vendor and product affected are OpenVPN, specific to Windows builds. The vulnerable releases include 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity risk, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need to be authenticated to the VPN server and must supply a client certificate containing a specially crafted subject string. If accepted, the flaw will trigger command execution within the VPN process context, exposing the system to compromise.
OpenCVE Enrichment