Bugzilla – Bug 1227511
VUL-0: CVE-2024-27459: openvpn: stack overflow in the interactive service component might lead to local privilege escalation
Last modified: 2024-07-08 12:42:41 UTC
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges. References: https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/ https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-27459 https://www.cve.org/CVERecord?id=CVE-2024-27459 https://community.openvpn.net/openvpn/wiki/CVE-2024-27459
As per [0]: "It's important to note that this issue is specific to Windows and is not all that easy to exploit". Therefore, this bug will be closed as we are seemingly not affected by this vulnerability. [0] https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/