CVE-2024-27903: Malicious File Upload
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-27903?
CVE-2024-27903 has a high severity rating as it allows an attacker to load arbitrary plug-ins with potential exploitation of the OpenVPN interactive service.
How do I fix CVE-2024-27903?
To fix CVE-2024-27903, update OpenVPN to version 2.6.10 or later to mitigate the vulnerability.
What versions of OpenVPN are affected by CVE-2024-27903?
OpenVPN versions 2.6.0 to 2.6.9 and all versions before 2.5.10 are affected by CVE-2024-27903.
What is the impact of exploiting CVE-2024-27903?
Exploiting CVE-2024-27903 can allow attackers to execute arbitrary code within the context of the OpenVPN service, leading to unauthorized access or control.
Is there a workaround for CVE-2024-27903 if I cannot update?
A temporary workaround for CVE-2024-27903 is to restrict the loading of plugins to specific, trusted directories until an update can be applied.