Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
The vulnerability results from improper handling of a local IPC (inter-process communication) channel by the background service of OpenVPN Connect. An attacker with local access can send crafted commands to this channel without the need for administrative privileges, authentication, or user interaction. Errors classified as CWE-78 (command injection), CWE-267, CWE-270, and CWE-648 indicate improper privilege management and insufficient input validation in the context of a privileged process.
An attacker can execute arbitrary system commands with elevated privileges, which in practice means the ability to take full control of the macOS system, including modification of system files, installation of malicious software, and establishment of persistence.
OpenVPN Connect should be updated to a version newer than 3.8.1. Detailed information about available patches can be found in the official release notes from the vendor: https://openvpn.net/connect-docs/macos-release-notes.html
OpenVPN Connect versions 3.5.1 to 3.8.1 on macOS
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XOpenvpn Connect
APPOpenvpn3.5.1 – 3.8.2 (excl.)
Related vulnerabilities
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is l...
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured,...
OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party ...
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an Ope...
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not ha...