Improper access control in OpenVPN for Windows - CVE-2024-24974
Published: March 20, 2024 / Updated: March 25, 2024
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions to the interactive service pipe. A remote user can bypass implemented security restrictions and gain unauthorized access to the application.
The vulnerability affects Windows installations only.
Affected software
SINEMA Remote Connect Client
How to mitigate CVE-2024-24974
SINEMA Remote Connect Client - update to 3.2 SP3