Blame

c4f02d Samuli Seppänen 2025-01-29 08:37:37 1
# CVE-2024-4877: Windows: A malicious process may spoof the interactive service and potentially impersonate a local user
2
4149f4 Samuli Seppänen 2025-02-27 10:18:21 3
interactive.c and OpenVPN-GUI for Windows:
c4f02d Samuli Seppänen 2025-01-29 08:37:37 4
437627 Samuli Seppänen 2025-02-27 10:18:40 5
If an attacker with SeImeprsonatePrivilege manages to create a namedpipe server with a name matching that used by the "Interactive Service", user interfaces such as OpenVPN-GUI connecting to it could allow the attacker to impersonate the user running the UI.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 6
4149f4 Samuli Seppänen 2025-02-27 10:18:21 7
To address this, we harden the security of the pipe, making it possible only for processes running as SYSTEM (such as the interactive service) create the pipe with the same name. Further, to protect against any such pipes created prior to startup of the service, clients of the service must match the PID of the pipe server with that of the service. This is implemented in OpenVPN-GUI for Windows.
c4f02d Samuli Seppänen 2025-01-29 08:37:37 8
4149f4 Samuli Seppänen 2025-02-27 10:18:21 9
### References
10
* Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html
4526e9 novaflash 2025-07-02 16:30:31 11
* CVE record: https://www.cve.org/CVERecord?id=CVE-2024-4877
4149f4 Samuli Seppänen 2025-02-27 10:18:21 12
* Reported by: Zeze with TeamT5 <zeze7w@gmail.com>