PT-2024-15241 · Openvpn+1 · Openvpn+1

Published

2024-02-21

·

Updated

2025-05-06

·

CVE-2023-7235

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenVPN versions prior to 2.6.9
Description The OpenVPN GUI installer did not set proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path. This allows an attacker to replace binaries and run arbitrary executables. The issue affects Windows GUI installations of OpenVPN.
Recommendations For versions prior to 2.6.9, update to version 2.6.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the installation directory of OpenVPN binaries to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

ALT-PU-2024-10859
ALT-PU-2024-10885
ALT-PU-2024-4639
CVE-2023-7235

Affected Products

Alt Linux
Openvpn