Blame

7da908 Samuli Seppänen 2025-02-27 10:16:41 1
# CVE-2024-27903: Windows: disallow loading of plugins from untrusted installation paths, which could be used to attack openvpn.exe via a malicious plugin
c4f02d Samuli Seppänen 2025-01-29 08:37:37 2
7da908 Samuli Seppänen 2025-02-27 10:16:41 3
win32: Enforce loading of plugins from a trusted directory
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
7da908 Samuli Seppänen 2025-02-27 10:16:41 5
Currently, there's a risk associated with allowing plugins to be loaded from any location. This update ensures plugins are only loaded from a trusted directory, which is either:
6
- HKLM\SOFTWARE\OpenVPN\plugin_dir (or if the key is missing, then HKLM\SOFTWARE\OpenVPN, which is installation directory)
7
- System directory
8
Loading from UNC paths is disallowed.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 9
7da908 Samuli Seppänen 2025-02-27 10:16:41 10
### References
11
* Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html
889fbe novaflash 2025-07-02 16:30:04 12
* CVE record: https://www.cve.org/CVERecord?id=CVE-2024-27903
7da908 Samuli Seppänen 2025-02-27 10:16:41 13
* Reported by: Vladimir Tokarev <​vtokarev@microsoft.com>