The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-10
https://thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html
https://www.microsoft.com/en-us/security/blog/2024/08/08/chained-for-attack-openvpn-vulnerabilities-discovered-leading-to-rce-and-lpe/
https://www.mail-archive.com/[email protected]/msg07534.html
https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/
https://community.openvpn.net/openvpn/wiki/CVE-2024-27459
Source: Mitre, NVD
Published: 2024-07-08
Updated: 2024-08-23
Base Score: 6.8
Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C
Severity: Medium
Base Score: 7.8
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.00855