Описание
The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths
A flaw was found in OpenVPN. The Windows Interactive Service allows local authenticated users to bypass security restrictions and load unauthorized configuration files. By crafting special paths, an attacker can manipulate the service's configuration, potentially leading to privilege escalation.
Отчет
This Moderate impact flaw affects the Windows Interactive Service in OpenVPN, enabling a local authenticated user to bypass configuration directory constraints and load arbitrary files. This can lead to privilege escalation on Windows systems. Red Hat's OpenVPN packages for Linux-based environments are not directly affected by this vulnerability.
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths
The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths
The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 al ...
The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths
EPSS
5.5 Medium
CVSS3