OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
2024-07-08T11:15:10.390
2024-11-21T09:05:23.177
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openvpn | openvpn | < 2.5.10 | Yes |
Application | openvpn | openvpn | < 2.6.10 | Yes |