Home
CRITICAL: 9.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HHIGH: 8.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDefault status
unaffected
3.5.1 (semver)
affected
Description
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
Problem types
CWE-267 Privilege defined with unsafe actions
CWE-270 Privilege context switching error
CWE-648 Incorrect use of privileged APIs
Product status
3.5.1 (semver)
References
openvpn.net/connect-docs/macos-release-notes.html