Executive brief
OpenVPN's Windows interactive service handles configuration files for VPN connections on Windows systems. A local authenticated user can bypass security restrictions that limit configuration files to a trusted directory, potentially allowing them to load malicious or unauthorized VPN configurations.
Technical details
The vulnerability is an improper path validation flaw in the Windows interactive service component of OpenVPN. Local authenticated users can bypass the trusted configuration directory constraint through incorrect file path validation logic, allowing them to reference configuration files outside the intended protected directory. Attack requires local authentication and presence on the target system. An attacker could exploit this to load arbitrary VPN configurations, potentially redirecting network traffic or gaining unauthorized access to VPN resources. Affected versions are 2.4.0 through 2.6.22.
Affected products
- OpenVPN OpenVPN 2.4.0 through 2.6.22
Timeline
- 2026-09-07: disclosed