CVE-2021-3606

HIGH

OpenVPN < 2.5.3 - Uncontrolled Search Path Element via OpenSSL Configuration File

Title source: llm
STIX 2.1

Description

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

References (2)

Core 2
Core References

Scores

CVSS v3 7.8
EPSS 0.0034
EPSS Percentile 26.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
openvpn/openvpn < 2.5.3
Published Jul 02, 2021
Tracked Since Feb 18, 2026