216.73.217.22

CVE-2024-4877

· Published 03/04/2025 16:15 · Modified 03/04/2025 16:15

Labels: CVE-2024-4877 2025-04-03CVE-2024-4877CWE-268[email protected]

Essential information

Published
03/04/2025 16:15
Modified
03/04/2025 16:15
Author
Creator
CISA KEV
No
CWE

Description

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
openvpn / openvpn cpe:2.3:a:openvpn:openvpn:2.4.0-2.6.10:*:*:*:*:*:*:*

References