Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-27903

33
FAUCET Score

CVE-2024-27903 is a critical vulnerability affecting OpenVPN plug-ins on Windows, specifically versions 2.6.9 and earlier. It allows an unauthenticated attacker to load arbitrary plug-ins from any directory, enabling interaction with the privileged OpenVPN interactive service. With a CVSS score of 9.8 (CRITICAL), this vulnerability presents a severe risk, allowing for complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention and media coverage, including a warning from Microsoft.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.5.10CPE matchmatch criteria
cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:*
>= 2.6.0, < 2.6.10CPE matchmatch criteria
cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
8.92%
Probability of exploitation in next 30 days
EPSS Percentile
94.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0892 is in the 90th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

giteapatch availablevia llm_extracted
Fixed in: 3.5.0
View patch
libreofficepatch availablevia llm_extracted
Fixed in: 3.5.0-136042
View patch
opencartpatch availablevia llm_extracted
Fixed in: 3.5.0
View patch
openvpnpatch availablevia llm_extracted
Fixed in: 3.5.0-136042
View patch
oroincpatch availablevia llm_extracted
Fixed in: 2.6.10, 2.5.10
View patch
leepeukervendor investigatingvia llm_extracted
View patch

Vendor Advisories (6)

oroincllm-oroinc-96198bd58817c096LOW

Privilege Escalation Vulnerabilities in OpenVPN GUI on Windows

May 6, 2024
giteallm-gitea-49456d1658a9e6bdMEDIUM

Private Key Exposure Vulnerability

openvpnllm-openvpn-3521358dda7974e3MEDIUM

Private Key Exposure Vulnerability in OpenVPN Connect Android

libreofficellm-libreoffice-562b1297865bc084

Private Key Exposure Vulnerability in OpenVPN Connect Android

opencartllm-opencart-25f41a566d1d779c

Private Key Exposure

leepeukerllm-leepeuker-e3266e2807cf81a9

References

community.openvpn.net / openvpn/wiki/CVE-2024-27903
Vendor Advisory
openvpn.net / security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974
Vendor Advisory
mail-archive.com / [email protected]/msg07534.html
Mailing List