CVE-2024-27459 is a stack overflow vulnerability in OpenVPN versions 2.6.9 and earlier, allowing an authenticated attacker to execute arbitrary code with elevated privileges through the interactive service. With a CVSS score of 7.8 (High), this local attack requires low privileges and user interaction, but can lead to complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code, the vulnerability has garnered significant community discussion and media attention, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.10CPE matchmatch criteria | cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:* | ||
>= 2.6.0, < 2.6.10CPE matchmatch criteria | cpe:2.3:a:openvpn:openvpn:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Privilege Escalation Vulnerabilities in OpenVPN GUI on Windows
May 6, 2024Private Key Exposure Vulnerability
Private Key Exposure Vulnerability in OpenVPN Connect Android
Private Key Exposure Vulnerability in OpenVPN Connect Android