ZeroHour

CVE-2026-84226

mass

Local Privilege Escalation via Binary Planting in OpenVPN for Windows

CVSS 4.0
8.5 high
EPSS
<1%p4
Published
()
Modified
AI analysis

OpenVPN 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows contain an untrusted search path flaw (CWE-426) that allows a binary planting attack while OpenVPN performs its network configuration steps. A local authenticated user can plant a malicious executable or library in a location searched ahead of the legitimate binary, which is then executed or loaded when those configuration steps run. Because the affected components operate in the context of the OpenVPN service, the attacker gains code execution with elevated privileges on the host, yielding a full local privilege escalation with high impact on confidentiality, integrity and availability of that system. Only OpenVPN deployments on Windows are affected; other platforms are not listed as impacted. Exploitation status is currently quiet: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns roughly a 0.1% probability of exploitation in the next 30 days.

What to do: Windows administrators should upgrade OpenVPN to a release after 2.6.22 (2.6.x branch) or after 2.7.6 (2.7.x branch) as published by OpenVPN, since those are the last affected versions in each branch and no fixed version is specified in the available data. As an interim mitigation, verify that standard users cannot write to the directories on the binary/library search path used by the OpenVPN service during network configuration, and watch for unexpected executables placed there. Check your installed client version (visible in the client's About/help output) to determine whether you are in an affected range.

Affected
OpenVPN Inc. OpenVPN (Windows client/service)2.5.0 through 2.6.22
OpenVPN Inc. OpenVPN (Windows client/service)2.7_alpha1 through 2.7.6
Estimated exposure
massplausibly millions of Windows installations running affected versions (OpenVPN is among the most widely deployed open-source VPN clients) — OpenVPN's Windows community installers have historically accumulated tens of millions of downloads and the client is embedded in Access Server and numerous third-party VPN offerings, so the count of Windows hosts running affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

OpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps

Weakness
CWE-426
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.