
Cloud Vulnerability DB
A community-led vulnerabilities database
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier contain a critical security vulnerability (CVE-2024-27903) that allows plugins to be loaded from any directory. This vulnerability was discovered in early 2024 and affects all versions of OpenVPN prior to versions 2.6.10 and 2.5.10. The issue received a CVSS v3.1 base score of 9.8 (Critical) from NIST (NVD).
The vulnerability resides in the plugin mechanism of OpenVPN's Windows implementation, specifically in the openvpnserv component. The flaw allows an attacker to load arbitrary plugins which can interact with the privileged OpenVPN interactive service. The vulnerability is classified under CWE-434 (Unrestricted Upload of File with Dangerous Type) and CWE-283 (Unverified Ownership) (NVD, OpenVPN Advisory).
If successfully exploited, this vulnerability could enable attackers to gain full control over targeted endpoints, potentially resulting in data breaches, system compromise, and unauthorized access to sensitive information. The attacker could leverage the vulnerability to interact with the privileged OpenVPN interactive service, leading to privilege escalation (Hacker News).
Exploitation requires user authentication and an advanced understanding of OpenVPN's inner workings. An attacker needs to either have valid credentials for a user that is part of the OpenVPN Administrator group or gain access through various methods including stolen credentials, stealer malware, or network traffic sniffing. The vulnerability can be chained with other OpenVPN flaws (CVE-2024-24974) to achieve remote code execution and local privilege escalation (OpenVPN Advisory).
The vulnerability has been fixed in OpenVPN versions 2.6.10 and 2.5.10. The fix improves the security of plugin loading on Windows by restricting plugins to only be loaded from certain trusted locations. Only OpenVPN Administrator can add to these trusted locations. Users are strongly advised to update to these patched versions (OpenVPN Advisory).
Microsoft's Threat Intelligence Community disclosed this vulnerability along with three other OpenVPN flaws at Black Hat USA 2024. The security community initially mischaracterized these as zero-day vulnerabilities, which OpenVPN clarified was incorrect as patches were already available when the details were published (OpenVPN Advisory, Hacker News).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."