CVE-2023-7245: High severity openvpn connect vulnerability
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRONRUNASNODE environment variable
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7245?
CVE-2023-7245 has been classified as a high severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2023-7245?
To fix CVE-2023-7245, upgrade OpenVPN Connect to version 3.4.4 or later for Windows and to version 3.4.8 or later for macOS.
Who is affected by CVE-2023-7245?
CVE-2023-7245 affects users of OpenVPN Connect versions 3.0 to 3.4.3 on Windows and 3.0 to 3.4.7 on macOS.
What exploit does CVE-2023-7245 enable?
CVE-2023-7245 enables a local user to execute arbitrary code within the nodejs process context.
Is CVE-2023-7245 a remote or local vulnerability?
CVE-2023-7245 is a local vulnerability that requires access to the system to exploit.