CVE-2024-4877: Windows: A malicious process may spoof the interactive service and potentially impersonate a local user
In interactive.c and OpenVPN-GUI for Windows:
A security vulnerability exists where an attacker without SeImeprsonatePrivilege could create a named pipe server with a name that matches the one used by the "Interactive Service". User interfaces such as OpenVPN-GUI, which connect to this named pipe, could be tricked into allowing the attacker to impersonate the user operating the interface.
To mitigate this issue, the security of the named pipe has been enhanced. Only processes running as SYSTEM (such as the interactive service) can now create a pipe with the same name. Additionally, to guard against any such pipes that were created before the service started, clients of the service are required to verify that the PID of the pipe server matches that of the service. These changes have been implemented in the OpenVPN-GUI for Windows.
References
- Release notes: https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html
- CVE record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4877
- Reported by: Zeze with TeamT5 zeze7w@gmail.com
