OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 10 Aug 2024 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Openvpn openvpn2
|
|
| Metrics |
ssvc
|
cvssV3_1
|
Status: PUBLISHED
Assigner: OpenVPN
Published: 2024-07-08T10:27:40.125Z
Updated: 2024-08-23T03:55:35.767Z
Reserved: 2024-03-12T18:26:01.705Z
Link: CVE-2024-27903
Updated: 2024-08-02T00:41:55.566Z
Status : Modified
Published: 2024-07-08T11:15:10.390
Modified: 2024-11-21T09:05:23.177
Link: CVE-2024-27903
No data.