OpenVPN Connect
cpe:2.3:a:openvpn:connect:*:*:*:*:macos:*:*
- >= 3.5.1, <= 3.8.1
A privilege escalation vulnerability has been identified in OpenVPN Connect versions 3.5.1 through 3.8.1 on macOS. This vulnerability allows attackers to execute arbitrary commands with elevated privileges by exploiting the background service's local inter-process communication (IPC) channel.
Exploitation of this vulnerability allows for unauthorized privilege escalation, enabling attackers to execute commands with elevated rights on the affected system.
Users can upgrade to OpenVPN Connect version 3.8.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.