CVE-2021-3613

HIGH

OpenVPN Connect 3.2.0-3.3.0 - Uncontrolled Search Path Element via OpenSSL Configuration File

Title source: llm
STIX 2.1

Description

OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0055
EPSS Percentile 41.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
openvpn/connect 3.2.0 - 3.3.0
Published Jul 02, 2021
Tracked Since Feb 18, 2026