wiki:CVE-2024-24974

CVE-2024-24974: Windows: disallow access to the interactive service pipe from remote computers

interactive.c: disable remote access to the service pipe

Remote access to the service pipe is not needed and might be a potential attack vector.

For example, if an attacker manages to get credentials for a user which is the member of "OpenVPN Administrators" group on a victim machine, an attacker might be able to communicate with the privileged interactive service on a victim machine and start openvpn processes remotely.

References

Last modified 6 weeks ago Last modified on 03/21/24 14:57:14