Commit 71818f

2025-02-27 10:15:18 Samuli Seppänen: Switch to non-AI version
Security Announcements/CVE-2024-24974.md ..
@@ 1,12 1,12 @@
- # CVE-2024-24974: Windows: Disallow Access to the Interactive Service Pipe from Remote Computers
+ # CVE-2024-24974: Windows: disallow access to the interactive service pipe from remote computers
- `interactive.c`: Disable remote access to the service pipe.
+ interactive.c: disable remote access to the service pipe
- Remote access to the service pipe is not necessary and could potentially serve as an attack vector.
+ Remote access to the service pipe is not needed and might be a potential attack vector.
- For instance, if an attacker obtains credentials for a user who is a member of the "OpenVPN Administrators" group on a target machine, they might be able to communicate with the privileged interactive service on that machine and initiate OpenVPN processes remotely.
+ For example, if an attacker manages to get credentials for a user which is the member of "OpenVPN Administrators" group on a victim machine, an attacker might be able to communicate with the privileged interactive service on a victim machine and start openvpn processes remotely.
- ## References
- - Release notes: [https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html](https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html)
- - CVE record: [https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974)
- - Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
\ No newline at end of file
+ ### References
+ * Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html
+ * CVE record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24974
+ * Reported by: Vladimir Tokarev <​vtokarev@microsoft.com>
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9