CVE-2024-27903: Windows: Disallow Loading of Plugins from Untrusted Installation Paths

This security update prevents openvpn.exe from being attacked through malicious plugins by enforcing that plugins are only loaded from a trusted directory.

Updated Plugin Loading Behavior

Plugins for OpenVPN on Windows platforms will now only be allowed to load from the following trusted directories:

  • Registry key HKLM\SOFTWARE\OpenVPN\plugin_dir. If this key is missing, then from HKLM\SOFTWARE\OpenVPN, which is the installation directory.
  • The system directory.

Note: Loading from UNC paths is specifically disallowed to increase security.

References

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9