Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-4877


OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges


Published

2025-04-03T16:15:32.840

Last Modified

2025-04-29T19:45:07.223

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-268
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openvpn openvpn < 2.6.11 Yes
Operating System microsoft windows - No

References