HIGH🇵🇱 Wersja polska

CVE-2021-3613

CVSS 7.8v3.1pub. 2021-07-02upd. 2024-11-21

OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Openvpn Connect

    APP
    Openvpn
    3.2.0 – 3.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPN
CWE
References

Related vulnerabilities

CVE-2026-9560CRITICAL9.4PL ✓same product

Privilege escalation w OpenVPN Connect na macOS — RCE z podwyższonymi uprawnieniami

CVE-2024-8474HIGH7.5same product

OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is l...

CVE-2023-7245HIGH7.8same product

The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured,...

CVE-2023-7224HIGH7.8same product

OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party ...

CVE-2020-15075HIGH7.1same product

OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not ha...