CVE Vulnerabilities

CVE-2024-4877

Privilege Chaining

Published: Apr 03, 2025 | Modified: Apr 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

Weakness

Two distinct privileges, roles, capabilities, or rights can be combined in a way that allows an entity to perform unsafe actions that would not be allowed without that combination.

Affected Software

Name Vendor Start Version End Version
Openvpn Openvpn 2.4.0 (including) 2.6.11 (excluding)

Potential Mitigations

References