CVE-2024-27903
CRITICALDescription
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| openvpn | openvpn |
| openvpn | openvpn |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-27903? +
How severe is CVE-2024-27903? +
What products are affected by CVE-2024-27903? +
How do I check if I'm vulnerable to CVE-2024-27903? +
Related Vulnerabilities
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged attacker could potentially exploit this …
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 …
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint …
Zemana AntiLogger v2.74.204.664 is vulnerable to an Arbitrary Process Termination vulnerability by triggering the 0x80002048 IOCTL code of the zam64.sys …
SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that are not normally …
In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the …