PT-2024-1066 · Openvpn · Openvpn Connect
Fatih
+1
·
Published
2024-01-08
·
Updated
2024-09-04
·
CVE-2023-7224
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenVPN Connect versions 3.0 through 3.4.6
Description
The issue is related to the failure to neutralize instructions in dynamically executed code. Exploitation of this issue may allow an attacker to execute arbitrary code using the
DYLD INSERT LIBRARIES environment variable. This can enable local users to execute code in external third-party libraries.Recommendations
For OpenVPN Connect versions 3.0 through 3.4.6, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting the use of the
DYLD INSERT LIBRARIES environment variable until a patch is available.Fix
Code Injection
Eval Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openvpn Connect