OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-10
https://thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html
https://www.microsoft.com/en-us/security/blog/2024/08/08/chained-for-attack-openvpn-vulnerabilities-discovered-leading-to-rce-and-lpe/
https://www.mail-archive.com/[email protected]/msg07534.html
https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/
https://community.openvpn.net/openvpn/wiki/CVE-2024-27903
Source: Mitre, NVD
Published: 2024-07-08
Updated: 2024-07-11
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.0031