# CVE-2024-27903

## Summary

- **CVE ID:** CVE-2024-27903
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-283
- **Published:** Jul 8, 2024
- **Last Modified:** Mar 13, 2026

## Description

OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.

## Affected Products

- OpenVPN — OpenVPN 2 (2.6.9 and earlier)

## References

- [CNA](https://community.openvpn.net/openvpn/wiki/CVE-2024-27903)
- [CNA](https://openvpn.net/security-advisory/ovpnx-vulnerability-cve-2024-27903-cve-2024-27459-cve-2024-24974/)
- [CNA](https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 8.92%
- **EPSS Percentile:** 94.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._