CVE-2024-4877
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
Scoring
- CVSS base score
- 0
- EPSS probability
- 0.43%
- CWE
- CWE-268
- Published
- 2025-04-03
- Last modified
- 2026-03-13
Affected products
- OpenVPN OpenVPN
Weakness type
Related vulnerabilities
- CVE-2026-32325 — Privilege chaining issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this...
- CVE-2026-3888 — Local Privilege Escalation in snapd
- CVE-2025-64701 — QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability,...
- CVE-2025-7973 — Rockwell Automation FactoryTalk® ViewPoint Privilege Escalation Vulnerability
- CVE-2025-36124 — IBM WebSphere Application Server Liberty bypass security
- CVE-2025-2297 — Privilege Management for Windows - Elevation of Privilege
- CVE-2025-49741 — Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- CVE-2025-20112 — Cisco Unified Communications Products Privilege Escalation Vulnerability