Описание
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
A flaw was found in OpenVPN. The Windows interactive service in OpenVPN contains an incorrect file path validation vulnerability. A local authenticated user could exploit this flaw to bypass the trusted configuration directory constraint, leading to a security bypass and potential integrity compromise.
Отчет
This Moderate vulnerability affects the Windows interactive service in OpenVPN, allowing local authenticated users to bypass trusted configuration directory constraints. As this issue is specific to the Windows platform, it does not directly impact Red Hat products.
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows ...
The Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation
EPSS
5.5 Medium
CVSS3