tag
Openvpn
None assigned as of 2026-07-03
network
HIGH
OpenVPN Connect Server-Pushed Option Current-User Command Execution
A malicious OpenVPN server can push an echo option to a connected OpenVPN Connect for Windows client that decodes into the internal script.win.user.disconnect script key. OpenVPN Connect then executes that pushed command when the client disconnects, even…
Unverified
2026-07-03