CVE-2021-3613: High severity OpenVPN Connect Windows vulnerability
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this OpenVPN Connect vulnerability?
The vulnerability ID is CVE-2021-3613.
What is the severity rating of CVE-2021-3613?
CVE-2021-3613 has a severity rating of 7.8 (high).
How does CVE-2021-3613 impact OpenVPN Connect?
CVE-2021-3613 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file, potentially allowing the execution of arbitrary code with the same privilege level as the main OpenVPN process.
Which versions of OpenVPN Connect are affected by CVE-2021-3613?
OpenVPN Connect versions 3.2.0 through 3.3.0 are affected by CVE-2021-3613.
Is there a fix available for CVE-2021-3613?
To fix CVE-2021-3613, users should update to a version of OpenVPN Connect that is not affected by the vulnerability.