]> git.ipfire.org Git - thirdparty/openvpn.git/commit
Windows security issue: v2.1.2
authorJames Yonan <james@openvpn.net>
Sun, 15 Aug 2010 21:53:00 +0000 (21:53 +0000)
committerJames Yonan <james@openvpn.net>
Sun, 15 Aug 2010 21:53:00 +0000 (21:53 +0000)
commit4f79d3ec453e8bc2621a847121b0086e0e86b165
tree7af6d8d74b22053e1a818cde5bca72983ddb3d76
parent379b549c81a8085c8134d46e55c6fbbd0884a404
Windows security issue:
Fixed potential local privilege escalation vulnerability in
Windows service. The Windows service did not properly quote the
executable filename passed to CreateService.  A local attacker
with write access to the root directory C:\ could create an
executable that would be run with the same privilege level as
the OpenVPN Windows service.  However, since non-Administrative
users normally lack write permission on C:\, this vulnerability
is generally not exploitable except on older versions of Windows
(such as Win2K) where the default permissions on C:\ would allow
any user to create files there.
Credit:  Scott Laurie, MWR InfoSecurity

Version 2.1.2

git-svn-id: http://svn.openvpn.net/projects/openvpn/branches/BETA21/openvpn@6400 e7ae566f-a301-0410-adde-c780ea21d3b5
ChangeLog
install-win32/settings.in
service-win32/service.c
version.m4