CVE-2021-27406: PerFact OpenVPN-Client
An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any application running on the local host machine to force the back-end server into initializing a new open-VPN instance with arbitrary open-VPN configuration. This could result in the attacker achieving execution with privileges of a SYSTEM user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27406?
CVE-2021-27406 is classified as a high-severity vulnerability due to its potential to allow arbitrary configuration commands that could impact the security of OpenVPN instances.
How do I fix CVE-2021-27406?
To fix CVE-2021-27406, upgrade to a version of PerFact OpenVPN-Client later than 1.4.1.0 that addresses this vulnerability.
What type of vulnerability is CVE-2021-27406?
CVE-2021-27406 is a local privilege escalation vulnerability affecting PerFact OpenVPN-Client that can be exploited from the local host machine.
Who is affected by CVE-2021-27406?
Users of PerFact OpenVPN-Client versions 1.4.1.0 and prior are affected by CVE-2021-27406.
Can CVE-2021-27406 be exploited remotely?
No, CVE-2021-27406 requires local access to the machine hosting the vulnerable version of PerFact OpenVPN-Client for exploitation.