Blame

71818f Samuli Seppänen 2025-02-27 10:15:18 1
# CVE-2024-24974: Windows: disallow access to the interactive service pipe from remote computers
c4f02d Samuli Seppänen 2025-01-29 08:37:37 2
71818f Samuli Seppänen 2025-02-27 10:15:18 3
interactive.c: disable remote access to the service pipe
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
71818f Samuli Seppänen 2025-02-27 10:15:18 5
Remote access to the service pipe is not needed and might be a potential attack vector.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 6
71818f Samuli Seppänen 2025-02-27 10:15:18 7
For example, if an attacker manages to get credentials for a user which is the member of "OpenVPN Administrators" group on a victim machine, an attacker might be able to communicate with the privileged interactive service on a victim machine and start openvpn processes remotely.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 8
71818f Samuli Seppänen 2025-02-27 10:15:18 9
### References
10
* Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html
a5ade6 novaflash 2025-07-02 16:29:31 11
* CVE record: https://www.cve.org/CVERecord?id=CVE-2024-24974
71818f Samuli Seppänen 2025-02-27 10:15:18 12
* Reported by: Vladimir Tokarev <​vtokarev@microsoft.com>