CyberzSOC

Publication detail
← Back to advisories & guidance

2024-076: Vulnerabilities in OpenVPN ↗ source

August 12, 2024 CERT-EU Advisory

Summary

On August 8, 2024, Microsoft released a writeup for those vulnerabilities [2]. openvpn.exe process and the openvpnserv.exe service. requests received through the \\openvpn\\service named pipe. be loaded from various paths on an endpoint device. In the project’s src folder, the device.c file contains the code for the TAP device object and its initialisation. You can find the complete technical explanation in the Microsoft report [2]. All versions of OpenVPN prior to version 2.6.10 (and 2.5.10).

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-1305 9.8 Critical OpenVPN tap-windows6 tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overf…
CVE-2024-24974 7.5 High OpenVPN OpenVPN 2 The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to inter…
CVE-2024-27459 7.2 High OpenVPN OpenVPN GUI The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary …
CVE-2024-27903 7.2 High OpenVPN OpenVPN 2 OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.