Permissions, Privileges, and Access Controls in OpenVPN for Windows - CVE-2024-4877
Published: June 20, 2024
OpenVPN for Windows
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions on the service pipe. A local user with SeImpersonatePrivilege permissions can open the pipe a second time, tricking openvn GUI into providing user credentials (tokens), and gain full access to the account used by openvpn-gui.exe.