CVE-2021-3606

Source
https://cve.org/CVERecord?id=CVE-2021-3606
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3606.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-3606
Published
2021-07-02T13:15:07.983Z
Modified
2026-03-14T11:01:31.270194Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (openvpn.exe).

References

Affected packages

Git / github.com/openvpn/openvpn

Affected ranges

Type
GIT
Repo
https://github.com/openvpn/openvpn
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.5.3"
        }
    ]
}

Affected versions

v2.*
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1_rc1
v2.1_rc10
v2.1_rc11
v2.1_rc12
v2.1_rc13
v2.1_rc14
v2.1_rc15
v2.1_rc16
v2.1_rc17
v2.1_rc18
v2.1_rc19
v2.1_rc2
v2.1_rc20
v2.1_rc21
v2.1_rc22
v2.1_rc3
v2.1_rc4
v2.1_rc5
v2.1_rc6
v2.1_rc7
v2.1_rc8
v2.1_rc9
v2.2-RC
v2.2-RC2
v2.2-beta4
v2.2-beta5
v2.3-alpha1
v2.3_alpha2
v2.3_alpha3
v2.3_beta1
v2.4_alpha1
v2.4_alpha2
v2.4_beta1
v2.4_beta2
v2.4_rc1
v2.4_rc2
v2.5.0
v2.5.1
v2.5.2
v2.5_beta1
v2.5_beta2
v2.5_beta3
v2.5_beta4
v2.5_rc1
v2.5_rc2
v2.5_rc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3606.json"