CVE-2024-24974: Windows: Disallow Access to the Interactive Service Pipe from Remote Computers

interactive.c: Disable remote access to the service pipe.

Remote access to the service pipe is not necessary and could potentially serve as an attack vector.

For instance, if an attacker obtains credentials for a user who is a member of the "OpenVPN Administrators" group on a target machine, they might be able to communicate with the privileged interactive service on that machine and initiate OpenVPN processes remotely.

References

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9