Report Finds Increasing Number of Vulnerabilities in OpenVPN

OpenVPN, an open source virtual private network (VPN) system integrated into millions of routers, firmware, PCs, mobile devices and other smart devices, is leaving users open to a growing list of threats, according to a recent report from Microsoft.

The company released a security report detailing some of the latest holes in the open source service, and is warning that many of these vulnerabilities could be used in conjunction "to achieve an attack chain consisting of remote code execution (RCE) and local privilege escalation (LPE)." The report was compiled after Microsoft discussed a handful of new OpenVPN holes during a session at Black Hat USA 2024.

Microsoft initially reported these vulnerabilities to OpenVPN in March 2024 through Coordinated Vulnerability Disclosure (CVD) via the Microsoft Security Vulnerability Research (MSVR) team. Following this, Microsoft and OpenVPN worked together to patch the vulnerabilities, culminating in the release of OpenVPN 2.6.10.   

The discovered vulnerabilities include:

  • CVE-2024-27459: Affects the openvpnserv component, leading to potential denial of service (DoS) and local privilege escalation (LPE) in Windows.
  • CVE-2024-24974: Also within openvpnserv, this vulnerability allows unauthorized access to Windows.
  • CVE-2024-27903: This flaw can result in remote code execution (RCE) on Windows and LPE or data manipulation on Android, iOS, macOS and BSD.
  • CVE-2024-1305: Affects the Windows TAP driver, leading to a potential DoS on Windows.

"All the identified vulnerabilities can be exploited once an attacker gains access to a user's OpenVPN credentials, which could be accomplished using credential theft techniques, such as purchasing stolen credentials on the dark web, using info-stealing malware, or sniffing network traffic to capture NTLMv2 hashes and then using cracking tools like HashCat or John the Ripper to decode them," wrote the Microsoft Threat Intelligence team.

What's interesting is that the discovered vulnerabilities all can be found on the client side. Microsoft stressed that OpennVPN's server is secure, and discovered no holes on that side of the equation.

Microsoft reported these vulnerabilities to OpenVPN in March 2024 through Coordinated Vulnerability Disclosure (CVD) via the Microsoft Security Vulnerability Research (MSVR) team. Following this, Microsoft and OpenVPN worked together to patch the vulnerabilities, culminating in the release of OpenVPN 2.6.10.  However, Microsoft said that users are strongly urged to apply the latest security updates to mitigate potential risks as soon as available.

Microsoft advises organizations using OpenVPN to verify their versions and apply the necessary patches immediately. In addition, ensuring strong credential management and limiting access to VPN services can further mitigate potential risks.

For more information, visit the Microsoft blog post.

About the Author

Chris Paoli (@ChrisPaoli5) is the associate editor for Converge360.

Featured

  • digital brain integrating legal regulation and security interface

    Survey: Agentic AI Moves from Pilot Phase to Production, Bringing Governance to the Forefront

    A new report from Caylent, an AI-focused Amazon Web Services Premier Tier Services Partner, found that enterprises are already moving agentic AI beyond pilots and into production environments. At the same time, organizations are putting strict conditions around autonomy, making governance and control the next major challenge for enterprise AI adoption.

  • abstract smartphone translucent screen displaying AI interface

    Apple Unveils Redesigned Siri AI

    At its recent Worldwide Developers Conference, Apple announced Siri AI, a redesigned version of its voice assistant that Apple describes in its own announcement as "a profoundly more capable and personal assistant." The update is intended to make Siri more conversational, more context-aware, and more useful across iPhone, iPad, Mac, Apple Watch, and Vision Pro.

  • large cloud icon with abstract code  and interconnected polygons

    Report: Enterprise AI Workloads Are Tipping Toward Private Cloud

    Broadcom's 2026 Private Coud Outlook report says enterprise AI is moving from experimentation into production, with private cloud emerging as the preferred deployment environment for AI inference among surveyed organizations.

  • education funding and graduation symbols on wooden dice

    What Is the Education Freedom Tax Credit and How Will It Work?

    The federal Education Freedom Tax Credit (EFTC) is a new source of funding for education that could benefit 90% of students in states that have opted in to the program. However, some confusion and misconceptions exist surrounding details of the program, including which programs may qualify, how parents can apply for scholarships, and how public school students can benefit.