CVE-2014-5455: Medium severity OpenVPN OpenVPN vulnerability
Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5455?
CVE-2014-5455 has a medium severity rating due to its potential for local privilege escalation.
How do I fix CVE-2014-5455?
To fix CVE-2014-5455, update to PrivateTunnel version 3.0 or OpenVPN Connect version 3.1 or later.
Who is affected by CVE-2014-5455?
CVE-2014-5455 affects local users running prior versions of PrivateTunnel and OpenVPN Connect on Windows.
What is the impact of CVE-2014-5455?
The impact of CVE-2014-5455 allows local users to execute their own crafted program and gain elevated privileges.
Is CVE-2014-5455 a zero-day vulnerability?
CVE-2014-5455 is not a zero-day vulnerability as it has been publicly disclosed and addressed by updates.