OpenVPN Windows NSIS installers have three vulnerabilities described in NSIS bug 1125. The most critical issue (!#1) enables running unsolicited code and an escalation of privilege attack through DLL Search Order Hijacking (CAPEC-471) since OpenVPN installers are typically executed with Admin privileges. NSIS/Windows prefers loading DLLs from the current directory, which for the Downloads folder, is user-writable. This makes the exploit straightforward to execute, but only if a malicious DLL has already been placed in the user's Downloads folder.
The following installers have been built with an NSIS version that includes fixes for the three bugs:
- openvpn-install-2.4.4-I601
- openvpn-install-2.3.18-I601
- openvpn-install-2.3.18-I001
However, based on our testing, Windows 7 may still be vulnerable to at least issue !#1 as it lacks the API calls used by the fix. Newer versions of Windows, such as Windows 2012r2, are not vulnerable if the updated installers are used. Because these issues are complex to fully address in executable installers, we strongly recommend not running any installers, including those from OpenVPN, directly from the Downloads directory.
Our long-term plan is to start distributing OpenVPN as an MSI package.
This issue was brought to our attention by Stefan Kanthak.
Further details:
