CVE-2021-3613

HIGH

Openvpn Connect < 3.3.0 - Uncontrolled Search Path

Title source: rule

Description

OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).

Scores

CVSS v3 7.8
EPSS 0.0007
EPSS Percentile 21.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-427
Status published

Affected Products (1)

openvpn/connect < 3.3.0

Timeline

Published Jul 02, 2021
Tracked Since Feb 18, 2026