Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78043

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

A flaw was found in OpenVPN. The Windows Interactive Service allows local authenticated users to bypass security restrictions and load unauthorized configuration files. By crafting special paths, an attacker can manipulate the service's configuration, potentially leading to privilege escalation.

Отчет

This Moderate impact flaw affects the Windows Interactive Service in OpenVPN, enabling a local authenticated user to bypass configuration directory constraints and load arbitrary files. This can lead to privilege escalation on Windows systems. Red Hat's OpenVPN packages for Linux-based environments are not directly affected by this vulnerability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2529298OpenVPN: OpenVPN: Privilege Escalation via Arbitrary Configuration File Loading

EPSS

Процентиль: 7%
0.00171
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
10 дней назад

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

nvd
10 дней назад

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

debian
10 дней назад

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 al ...

github
10 дней назад

The Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths

EPSS

Процентиль: 7%
0.00171
Низкий

5.5 Medium

CVSS3