CVE-2024-4877
Essential information
- Published
- 03/04/2025 16:15
- Modified
- 03/04/2025 16:15
- Author
- —
- Creator
- —
- CISA KEV
- No
- CWE
- —
- CVSS vector
- — — —
Description
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
NVD status
- Status
- Received — CVE has been recently published to the CVE List and has been received by the NVD.
- Source
- [email protected]
- NVD
- View on NVD
Affected products (CPE)
| Product | CPE |
|---|---|
| openvpn / openvpn | cpe:2.3:a:openvpn:openvpn:2.4.0-2.6.10:*:*:*:*:*:*:* |