CVE-2024-4877
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 3, 2025
Updated: Apr 7, 2025
CWE ID 268
Summary
CVE-2024-4877 is a vulnerability affecting OpenVPN versions 2.4.0 through 2.6.10 on Windows. An external, less privileged process can create a named pipe, which is then connected by the OpenVPN GUI component. By exploiting this vulnerability, the attacker can escalate their privileges and gain higher access to the system. The OpenVPN software mistakenly grants the GUI component unnecessary permissions, enabling the attack. This security flaw poses a significant risk and requires immediate patching to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OpenVPN