Blame
| 7da908 | Samuli Seppänen | 2025-02-27 10:16:41 | 1 | # CVE-2024-27903: Windows: disallow loading of plugins from untrusted installation paths, which could be used to attack openvpn.exe via a malicious plugin |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 2 | |
| 7da908 | Samuli Seppänen | 2025-02-27 10:16:41 | 3 | win32: Enforce loading of plugins from a trusted directory |
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 4 | |
| 7da908 | Samuli Seppänen | 2025-02-27 10:16:41 | 5 | Currently, there's a risk associated with allowing plugins to be loaded from any location. This update ensures plugins are only loaded from a trusted directory, which is either: |
| 6 | - HKLM\SOFTWARE\OpenVPN\plugin_dir (or if the key is missing, then HKLM\SOFTWARE\OpenVPN, which is installation directory) |
|||
| 7 | - System directory |
|||
| 8 | Loading from UNC paths is disallowed. |
|||
| c4f02d | Samuli Seppänen | 2025-01-29 08:37:37 | 9 | |
| 7da908 | Samuli Seppänen | 2025-02-27 10:16:41 | 10 | ### References |
| 11 | * Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html |
|||
| 889fbe | novaflash | 2025-07-02 16:30:04 | 12 | * CVE record: https://www.cve.org/CVERecord?id=CVE-2024-27903 |
| 7da908 | Samuli Seppänen | 2025-02-27 10:16:41 | 13 | * Reported by: Vladimir Tokarev <vtokarev@microsoft.com> |
