Commit 7da908

2025-02-27 10:16:41 Samuli Seppänen: Switch to non-AI version
Security Announcements/CVE-2024-27903.md ..
@@ 1,18 1,13 @@
- # CVE-2024-27903: Windows: Disallow Loading of Plugins from Untrusted Installation Paths
+ # CVE-2024-27903: Windows: disallow loading of plugins from untrusted installation paths, which could be used to attack openvpn.exe via a malicious plugin
- **This security update prevents `openvpn.exe` from being attacked through malicious plugins by enforcing that plugins are only loaded from a trusted directory.**
+ win32: Enforce loading of plugins from a trusted directory
- ## Updated Plugin Loading Behavior
+ Currently, there's a risk associated with allowing plugins to be loaded from any location. This update ensures plugins are only loaded from a trusted directory, which is either:
+ - HKLM\SOFTWARE\OpenVPN\plugin_dir (or if the key is missing, then HKLM\SOFTWARE\OpenVPN, which is installation directory)
+ - System directory
+ Loading from UNC paths is disallowed.
- Plugins for OpenVPN on Windows platforms will now only be allowed to load from the following trusted directories:
-
- - Registry key `HKLM\SOFTWARE\OpenVPN\plugin_dir`. If this key is missing, then from `HKLM\SOFTWARE\OpenVPN`, which is the installation directory.
- - The system directory.
-
- **Note**: Loading from UNC paths is specifically disallowed to increase security.
-
- ## References
-
- - [Release notes](https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html)
- - [CVE record](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27903)
- - Reported by: Vladimir Tokarev <vtokarev@microsoft.com>
\ No newline at end of file
+ ### References
+ * Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html
+ * CVE record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27903
+ * Reported by: Vladimir Tokarev <​vtokarev@microsoft.com>
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9