CVE-2024-27903: Windows: Disallow Loading of Plugins from Untrusted Installation Paths
This security update prevents openvpn.exe from being attacked through malicious plugins by enforcing that plugins are only loaded from a trusted directory.
Updated Plugin Loading Behavior
Plugins for OpenVPN on Windows platforms will now only be allowed to load from the following trusted directories:
- Registry key
HKLM\SOFTWARE\OpenVPN\plugin_dir. If this key is missing, then fromHKLM\SOFTWARE\OpenVPN, which is the installation directory. - The system directory.
Note: Loading from UNC paths is specifically disallowed to increase security.
References
- Release notes
- CVE record
- Reported by: Vladimir Tokarev vtokarev@microsoft.com
