Commit a3675e

2025-02-27 10:31:23 Samuli Seppänen: Switch to non-AI version
Security Announcements/UnquotedServicePathIn24WindowsInstallers.md ..
@@ 1,36 1,41 @@
- # Introduction
+ # Introduction
- Commit [8795ccfd25](https://github.com/OpenVPN/openvpn-build/commit/8795ccfd251b8252122dec43e6327a74856d17db) to openvpn-build made the NSIS installer manage services using SimpleSC NSIS plugin. The new service management commands did not properly quote service paths which created a subtle medium-level vulnerability. The vulnerability can be exploited if two conditions are met:
+ Commit [8795ccfd25](https://github.com/OpenVPN/openvpn-build/commit/8795ccfd251b8252122dec43e6327a74856d17db) to openvpn-build made the NSIS installer manage services using SimpleSC NSIS plugin. The new service management commands did not properly quote service paths which created a subtle medium-level vulnerability. The vulnarability can be exploited if two conditions are met:
- - The C:\ drive is writable by limited user(s)
- - OpenVPN was installed using official **OpenVPN 2.4** Windows installers
+ * The C:\ drive is writeable by limited user(s)
+ * OpenVPN was installed using official **OpenVPN 2.4** Windows installers
Users of such systems are urged to upgrade to openvpn-install-2.4.3-I602 or later as soon as possible.
Thanks to Jason Haar for finding and reporting this issue! The original Nessus report is available below.
- # Original Nessus report
+ # Original Nessus report
- ## Description
+ ## Description
- The remote Windows host has at least one service installed that uses an unquoted service path, which contains at least one whitespace. A local attacker can gain elevated privileges by inserting an executable file in the path of the affected service.
+ The remote Windows host has at least one service installed that uses an
+ unquoted service path, which contains at least one whitespace. A local
+ attacker can gain elevated privileges by inserting an executable file in
+ the path of the affected service.
- Note that this is a generic test that will flag any application affected by the described vulnerability.
+ Note that this is a generic test that will flag any application affected
+ by the described vulnerability.
- ## Solution
+ ## Solution
- Ensure that any services that contain a space in the path enclose the path in quotes.
+ Ensure that any services that contain a space in the path enclose the
+ path in quotes.
- ## See Also
+ ## See Also
- - [Nessus Reference](http://www.nessus.org/u?84a4cc1c)
- - [CWE-428](http://cwe.mitre.org/data/definitions/428.html)
- - [Common Exploits on Unquoted Service Paths](https://www.commonexploits.com/unquoted-service-paths/)
- - [Nessus Documentation](http://www.nessus.org/u?4aa6acbc)
+ * http://www.nessus.org/u?84a4cc1c
+ * http://cwe.mitre.org/data/definitions/428.html
+ * https://www.commonexploits.com/unquoted-service-paths/
+ * http://www.nessus.org/u?4aa6acbc
- ## Output
+ ## Output
- Nessus found the following services with an untrusted path:
+ Nessus found the following services with an untrusted path:
- - OpenVPNServiceLegacy: `C:\Program Files\OpenVPN\bin\openvpnserv.exe`
- - OpenVPNServiceInteractive: `C:\Program Files\OpenVPN\bin\openvpnserv.exe`
\ No newline at end of file
+ * OpenVPNServiceLegacy : C:\Program Files\OpenVPN\bin\openvpnserv.exe
+ * OpenVPNServiceInteractive : C:\Program Files\OpenVPN\bin\openvpnserv.exe
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9