# CVE-2024-4877

## Summary

- **CVE ID:** CVE-2024-4877
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-268
- **Published:** Apr 3, 2025
- **Last Modified:** Mar 13, 2026

## Description

OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges

## Affected Products

- OpenVPN — OpenVPN (2.4.0)

## References

- [CNA](https://community.openvpn.net/openvpn/wiki/CVE-2024-4877)
- [CNA](https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07634.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.43%
- **EPSS Percentile:** 35.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._