CVE-2023-7235: OpenVPN 2.x GUI Privilege Escalation Possible if Installed Outside Default Installation Path on Windows
When OpenVPN 2 GUI is installed on Windows in a non-standard installation directory, the installation directory's access control is not properly restricted. Windows, by default, assigns very open permissions, making any directory outside of standard system paths writable to anyone. This vulnerability allows an attacker to replace the OpenVPN service component with malicious code, gaining increased control over the host when the OpenVPN service process is restarted.
References
- Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07456.html
- CVE record: https://www.cve.org/CVERecord?id=CVE-2023-7235
- Reported by: Will Dormann (Analygence, Inc)
