Commit d4014c

2025-02-27 10:22:03 Samuli Seppänen: Switch to non-AI version
Security Announcements/NSISBug1125.md ..
@@ 1,20 1,20 @@
- OpenVPN Windows NSIS installers have three vulnerabilities described in [NSIS bug 1125](https://sourceforge.net/p/nsis/bugs/1125/). The most critical issue (!#1) enables running unsolicited code and an escalation of privilege attack through DLL Search Order Hijacking ([CAPEC-471](https://capec.mitre.org/data/definitions/471.html)) since OpenVPN installers are typically executed with Admin privileges. NSIS/Windows prefers loading DLLs from the current directory, which for the Downloads folder, is user-writable. This makes the exploit straightforward to execute, but only if a malicious DLL has already been placed in the user's Downloads folder.
+ OpenVPN Windows NSIS installers have three vulnerabilities described in [NSIS bug 1125](https://sourceforge.net/p/nsis/bugs/1125/). The most serious of these issues (!#1) allows running unsolicited code and an escalation of privilege attack using DLL Search Order Hijacking ([CAPEC-471](https://capec.mitre.org/data/definitions/471.html)) as OpenVPN installers are generally executed with Admin privileges. What NSIS/Windows does is actually prefer loading DLLs in the current directory, which in case of the Downloads folder is writable by the user. Thus the exploit is trivial to exploit, but only if the attacker has already managed to get a malicious DLL into user's Downloads folder
- The following installers have been built with an NSIS version that includes fixes for the three bugs:
+ The following installers have been built with an NSIS version which includes fixes for the three bugs:
- - openvpn-install-2.4.4-I601
- - openvpn-install-2.3.18-I601
- - openvpn-install-2.3.18-I001
+ * openvpn-install-2.4.4-I601
+ * openvpn-install-2.3.18-I601
+ * openvpn-install-2.3.18-I001
- However, based on our testing, Windows 7 may still be vulnerable to at least issue !#1 as it lacks the API calls used by the fix. Newer versions of Windows, such as Windows 2012r2, are not vulnerable if the updated installers are used. Because these issues are complex to fully address in executable installers, we strongly recommend **not** running any installers, including those from OpenVPN, directly from the Downloads directory.
+ Based on our testing, though, Windows 7 may still suffer from at least problem !#1 as it is lacks the API calls used by the fix. Newer Windows versions - at least Windows 2012r2 - are not vulnerable if updated installers are used. Because this type of issues are very tricky to fully fix in executable installer we strongly recommend *not* to run any installers, including OpenVPN's, directly from the Downloads directory.
- Our long-term plan is to start distributing OpenVPN as an MSI package.
+ Our long term plan is to start distributing OpenVPN as an MSI package instead.
This issue was brought to our attention by Stefan Kanthak.
Further details:
- - [NSIS bug 1125](https://sourceforge.net/p/nsis/bugs/1125/)
- - [CAPEC-471](https://capec.mitre.org/data/definitions/471.html)
- - [Windows Desktop API reference](https://msdn.microsoft.com/en-us/library/windows/desktop/hh310515(v=vs.85).aspx)
- - [Larry Osterman's blog on MSDN](http://blogs.msdn.com/b/larryosterman/archive/2004/07/19/187752.aspx)
\ No newline at end of file
+ * https://sourceforge.net/p/nsis/bugs/1125/
+ * https://capec.mitre.org/data/definitions/471.html
+ * https://msdn.microsoft.com/en-us/library/windows/desktop/hh310515%28v=vs.85%29.aspx
+ * http://blogs.msdn.com/b/larryosterman/archive/2004/07/19/187752.aspx
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9