Описание
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | Windows only |
esm-infra-legacy/trusty | not-affected | Windows only |
esm-infra/bionic | not-affected | Windows only |
esm-infra/focal | not-affected | Windows only |
esm-infra/xenial | not-affected | Windows only |
focal | not-affected | Windows only |
jammy | not-affected | Windows only |
mantic | ignored | end of life, was needs-triage |
noble | not-affected | Windows only |
trusty/esm | not-affected | Windows only |
Показывать по
Ссылки на источники
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be lo ...
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
Уязвимость компонента Plug-in Handler программного обеспечения OpenVPN, позволяющая нарушителю загружать произвольные модули
EPSS
9.8 Critical
CVSS3