mirror of https://github.com/OpenVPN/openvpn-gui
Browse Source
Commit 791aea49e6
cherry-picked from
master. Commit message altered to make it more relevant for this version.
Connecting to a named pipe server while running with admin rights is not
secure in some windows versions. Even if interactive service is not installed,
the GUI attempts to connect to the service pipe making it possible to exploit
this. Windows XP is known to be vulnerable. See also
http://nsylvain.blogspot.ca/2008/01/namedpipe-impersonation-attack.html
Signed-off-by: Selva Nair <selva.nair@gmail.com>
pull/22/head
Selva Nair
9 years ago
3 changed files with 31 additions and 2 deletions
Loading…
Reference in new issue