2025-02-27 10:16:41Samuli Seppänen:
Switch to non-AI version
Security Announcements/CVE-2024-27903.md ..
@@ 1,18 1,13 @@
-
# CVE-2024-27903: Windows: Disallow Loading of Plugins from Untrusted Installation Paths
+
# CVE-2024-27903: Windows: disallow loading of plugins from untrusted installation paths, which could be used to attack openvpn.exe via a malicious plugin
-
**This security update prevents `openvpn.exe` from being attacked through malicious plugins by enforcing that plugins are only loaded from a trusted directory.**
+
win32: Enforce loading of plugins from a trusted directory
-
## Updated Plugin Loading Behavior
+
Currently, there's a risk associated with allowing plugins to be loaded from any location. This update ensures plugins are only loaded from a trusted directory, which is either:
+
- HKLM\SOFTWARE\OpenVPN\plugin_dir (or if the key is missing, then HKLM\SOFTWARE\OpenVPN, which is installation directory)
+
- System directory
+
Loading from UNC paths is disallowed.
-
Plugins for OpenVPN on Windows platforms will now only be allowed to load from the following trusted directories:
-
-
- Registry key `HKLM\SOFTWARE\OpenVPN\plugin_dir`. If this key is missing, then from `HKLM\SOFTWARE\OpenVPN`, which is the installation directory.
-
- The system directory.
-
-
**Note**: Loading from UNC paths is specifically disallowed to increase security.