Описание
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
A flaw was found in OpenVPN on Windows. A local authenticated user could perform a binary planting attack during network configuration steps. This vulnerability could allow the attacker to execute arbitrary code or escalate privileges on the affected system.
Отчет
The vulnerability is rated as Important because it allows local authenticated users to achieve arbitrary code execution via a binary planting attack during network configuration steps. However, this flaw specifically affects OpenVPN on Windows platforms. Red Hat's OpenVPN packages, available in Community Projects like Fedora and EPEL, are built for Linux environments and are not susceptible to this Windows-specific vulnerability.
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on W ...
OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps
EPSS
7.8 High
CVSS3