CVE-2024-27903
08.07.2024, 11:15
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.Enginsight
Vendor | Product | Version |
---|---|---|
openvpn | openvpn | 𝑥 < 2.5.10 |
openvpn | openvpn | 2.6.0 ≤ 𝑥 < 2.6.10 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
- CWE-283 - Unverified OwnershipThe software does not properly verify that a critical resource is owned by the proper entity.
- CWE-434 - Unrestricted Upload of File with Dangerous TypeThe software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.
References