Vulnerability Details CVE-2020-9442
OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.02
EPSS Ranking 83.1%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2020-9442
-
cpe:2.3:a:openvpn:connect:1.1.17
-
cpe:2.3:a:openvpn:connect:1.1.21
-
cpe:2.3:a:openvpn:connect:1.1.22
-
cpe:2.3:a:openvpn:connect:1.1.23
-
cpe:2.3:a:openvpn:connect:1.1.24
-
cpe:2.3:a:openvpn:connect:1.1.25
-
cpe:2.3:a:openvpn:connect:1.1.26
-
cpe:2.3:a:openvpn:connect:1.1.27
-
cpe:2.3:a:openvpn:connect:3.0.0
-
cpe:2.3:a:openvpn:connect:3.0.0_(820)
-
cpe:2.3:a:openvpn:connect:3.0.0_(870)
-
cpe:2.3:a:openvpn:connect:3.0.1
-
cpe:2.3:a:openvpn:connect:3.0.1_(884)
-
cpe:2.3:a:openvpn:connect:3.0.1_(885)
-
cpe:2.3:a:openvpn:connect:3.0.1_(895)
-
cpe:2.3:a:openvpn:connect:3.0.1_(918)
-
cpe:2.3:a:openvpn:connect:3.0.2
-
cpe:2.3:a:openvpn:connect:3.0.3
-
cpe:2.3:a:openvpn:connect:3.0.4
-
cpe:2.3:a:openvpn:connect:3.0.5
-
cpe:2.3:a:openvpn:connect:3.0.6
-
cpe:2.3:a:openvpn:connect:3.0.7
-
cpe:2.3:a:openvpn:connect:3.1.0
-
cpe:2.3:a:openvpn:connect:3.1.0.361
-
cpe:2.3:o:microsoft:windows:-