OSINT & Modern Recon Uncover Global VPN Infrastructure
Vladimir Tokarev (Senior Security Researcher · Microsoft)
Recon Village @ DEF CON 33 · Day 1 · Recon Village
Overview
In this compelling presentation from Recon Village, Vladimir Tokarev, a Senior Security Researcher at Microsoft, unveils a series of critical vulnerabilities impacting the widely used OpenVPN infrastructure. The talk, titled "OSINT & Modern Recon Uncover Global VPN Infrastructure," details a fascinating journey from a casual dare to a sophisticated full attack chain, demonstrating how seemingly isolated bugs can ripple through global systems due to shared codebases and architectural patterns. Tokarev meticulously dissects the technical intricacies of these vulnerabilities, showcasing their potential for severe impact, ranging from local privilege escalation (LPE) to remote code execution (RCE) and even bypassing advanced kernel protections.

Key moments
- 0:00 Introduction: The 'dare' that started the research
- 2:25 Initial bug discovery in ExpressVPN's TAP driver
- 4:00 Detailed explanation of the integer overflow vulnerability
- 5:30 Challenges of exploiting kernel copy overflows
- 6:10 Realizing a systematic issue: Same bug in ProtonVPN
- 6:40 Using Yara rules to find 50 affected drivers
- 7:30 Identifying OpenVPN as the common underlying cause
- 8:15 Confirming the bug in OpenVPN's tap-windows6 source code
OSINT & Modern Recon Uncover Global VPN Infrastructure
Speakers: Vladimir Tokarev, Senior Security Researcher, Microsoft
Conference: Recon Village
YouTube: https://www.youtube.com/watch?v=4HGFlZZfWc8
Overview
In this compelling presentation from Recon Village, Vladimir Tokarev, a Senior Security Researcher at Microsoft, unveils a series of critical vulnerabilities impacting the widely used OpenVPN infrastructure. The talk, titled "OSINT & Modern Recon Uncover Global VPN Infrastructure," details a fascinating journey from a casual dare to a sophisticated full attack chain, demonstrating how seemingly isolated bugs can ripple through global systems due to shared codebases and architectural patterns. Tokarev meticulously dissects the technical intricacies of these vulnerabilities, showcasing their potential for severe impact, ranging from local privilege escalation (LPE) to remote code execution (RCE) and even bypassing advanced kernel protections.
The research not only exposes specific flaws in OpenVPN's Windows components but also highlights the profound power of open-source intelligence (OSINT) and modern reconnaissance techniques in identifying systemic security risks. By leveraging tools like Yara rules, VirusTotal, Shodan, and cloud-based cracking platforms, Tokarev illustrates a practical methodology for discovering widespread vulnerabilities and building complex exploit chains. This talk serves as a critical wake-up call for VPN providers and users alike, emphasizing the necessity of robust security practices in software that underpins global privacy and secure communication.
The significance of this research cannot be overstated given OpenVPN's pervasive adoption across countless commercial VPN services, enterprise networks, and even embedded systems like routers. The disclosed attack vectors demonstrate how an attacker, with sufficient reconnaissance and technical prowess, could compromise endpoints, escalate privileges, and gain arbitrary control, ultimately undermining the very security and privacy that VPNs are designed to provide.
Background
▶ Watch: Introduction: The 'dare' that started the research (0:00)
The genesis of this extensive research began unexpectedly during a gaming session. Vladimir Tokarev's friend, experiencing connectivity issues with a newly installed ExpressVPN client, challenged him to find flaws in the service. This personal dare prompted Tokarev to investigate ExpressVPN's components, specifically its Windows driver. His initial reverse engineering efforts quickly uncovered a critical integer overflow vulnerability within the TAP adapter driver, a virtual network card implementation commonly used by VPNs on Windows.
Realizing this might not be an isolated incident, Tokarev broadened his scope. He crafted Yara rules to identify the specific problematic memory allocation pattern in driver binaries, then leveraged VirusTotal to scan for matches. This yielded over 50 drivers exhibiting the same vulnerability, strongly suggesting a systemic issue rather than a one-off bug. Further investigation, aided by asking ChatGPT about the most popular VPNs, pointed directly to OpenVPN as the likely common denominator. OpenVPN, being a vast open-source project, serves as the backbone for numerous commercial VPN services, including ExpressVPN, ProtonVPN, NordVPN, and CyberGhost, explaining the widespread nature of the discovered flaw.
Delving into the OpenVPN codebase, specifically the TapWindows6 repository, Tokarev pinpointed the exact source of the integer overflow: a macro within the memory allocation logic that incorrectly calculated buffer sizes. This discovery validated his hypothesis that a single, foundational bug could propagate across a global infrastructure due to shared and reused components. This initial finding laid the groundwork for a much deeper exploration into OpenVPN's architecture and the discovery of further vulnerabilities that could be chained together for devastating effects.
Key Findings
▶ Watch: Detailed explanation of the integer overflow vulnerability (4:00)
Vladimir Tokarev's research uncovered a series of interconnected vulnerabilities and exploitation techniques, culminating in a powerful attack chain:
- Widespread Integer Overflow in TAP Drivers: The initial discovery was an integer overflow vulnerability in the TAP driver (specifically within the
TapWindows6component of OpenVPN), affecting how network buffers are allocated. This bug, caused by an incorrect calculation ofpacket_length + additional_error_size, could lead to kernel memory corruption. While direct exploitation for arbitrary code execution is challenging due to modern kernel mitigations, its presence in over 50 drivers highlighted a systemic risk across the VPN ecosystem. - Stack Overflow in OpenVPN Windows Service: A critical stack overflow vulnerability was identified in the OpenVPN service on Windows. This flaw resides in the
handle_messagefunction, which processes data received from the OpenVPN daemon via an inter-process communication (IPC) named pipe. By sending an oversized message, an attacker could overflow a stack-allocated union, potentially leading to a denial-of-service or, under specific conditions, local privilege escalation (LPE). However, the presence of stack cookies (canaries) makes direct exploitation for arbitrary code execution difficult, typically resulting in a process crash. - Named Pipe Race Condition and Impersonation: The OpenVPN Windows service relies heavily on named pipes for communication. Tokarev demonstrated how an attacker could exploit a named pipe instance race condition or superflow pipe connectivity issue. By creating a malicious named pipe with the same name as the legitimate OpenVPN service pipe (
OpenVPN/service) after crashing the original service, an attacker can intercept client connections and impersonate the service, gaining control over subsequent client interactions. - Remote Code Execution (RCE) via Malicious Plugin Load: A sophisticated RCE vector was developed by combining several steps:
- Network Reconnaissance and Credential Theft: Sniffing NLMv2 hashes from network traffic (e.g., using Responder).
- Cloud-Based Hash Cracking: Utilizing powerful cloud GPU resources (like vast.ai) to rapidly crack NLMv2 hashes, obtaining valid user credentials. For example, a 9-character password was cracked in less than 3 minutes using 18 RTX 4090 GPUs.
- Remote IPC Access: Using the cracked credentials to access remote Windows endpoints via SMB/IPC$ shares, specifically targeting the OpenVPN service named pipe.
- Malicious Plugin Injection: Passing a crafted OpenVPN configuration to the remote service, instructing the OpenVPN daemon to load a malicious plugin (a specially crafted DLL) from an attacker-controlled SMB share. This allows arbitrary code execution on the remote endpoint.
- Full Attack Chain: RCE -> LPE -> Kernel Read/Write -> PPL Bypass: The ultimate finding was a complete, multi-stage attack chain:
- Remote Code Execution: Gaining initial RCE on the target via the malicious plugin load.
- Local Privilege Escalation: The plugin then triggers the LPE logic (leveraging the named pipe impersonation and service crash technique).
- Kernel Read/Write Primitives: The LPE leads to the ability to load a vulnerable driver or exploit a 1-day/0-day vulnerability (e.g., in Windows'
appid.sysor similar) to achieve arbitrary kernel read/write primitives. - Protected Process Light (PPL) Bypass: Using these kernel primitives, the attacker can overwrite the
PS_PROTECTIONstructure of a Protected Process Light (PPL) protected process (e.g.,wininit.exe), effectively disabling its protection and allowing termination or manipulation by lower-privileged processes. This provides a high level of stealth and persistence, allowing attackers to disable security software.
Technical Deep Dive
▶ Watch: Realizing a systematic issue: Same bug in ProtonVPN (6:10)
The technical depth of this research spans multiple layers of the OpenVPN architecture and Windows internals.
TAP Driver Integer Overflow Details:
The initial vulnerability stems from the TapAdapterTransmit function within the TapWindows6 driver, responsible for handling network packets. This function allocates memory for incoming data using NdisAllocateNetBufferList, where the size is calculated as packet_length + 24 additional bytes. Subsequently, it attempts to copy packet_length + 18 bytes into this newly allocated buffer. The core issue lies in a macro, likely ADD_PACKET_LENGTH, which computes packet_length + additional_error_size without proper overflow checks. If packet_length is sufficiently large, this addition can cause an integer overflow, resulting in a smaller-than-expected memory allocation. When the subsequent memory copy operation (NdisGetDataBuffer followed by NdisMoveMemory) attempts to copy the originally intended (and now much larger) amount of data into the undersized buffer, a kernel overflow occurs. While kernel overflows are notoriously difficult to exploit for reliable RCE due to modern mitigations like HVCI (Hypervisor-Enforced Code Integrity) and demap (Device Guard), their widespread presence in over 50 drivers indicates a significant underlying design flaw.
OpenVPN Architecture on Windows:
Understanding OpenVPN's Windows architecture is crucial for the LPE and RCE vectors. The system relies on two main components:
- OpenVPN server (service): A Windows service running at
SYSTEMlevel. It exposes a well-known named pipe calledOpenVPN/service. Its primary role is to manage instances of the OpenVPN daemon. - OpenVPN daemon: The actual
openvpn.exeprocess that performs the VPN tunneling, encryption, and decryption. It typically runs as the user who initiated the connection.
When a client (e.g., OpenVPN GUI) wants to start a VPN connection, it connects to the OpenVPN/service named pipe. It sends startup_data (containing the configuration file path, log file path, and working directory) to the service. The OpenVPN server then impersonates the connecting client. Crucially, it validates that the client belongs to the OpenVPN user group before proceeding. If validated, the service launches an openvpn.exe daemon process as the impersonated user. This daemon then establishes a second named pipe (e.g., service1234) through which it communicates back to the OpenVPN server for privileged actions, such as modifying DNS settings or adding routes to the system, which the unprivileged user daemon cannot do directly.
OpenVPN Service Stack Overflow (LPE):
The stack overflow vulnerability resides in the OpenVPN server's handling of messages received from the OpenVPN daemon via this second, inner named pipe. Specifically, the handle_message function allocates a union message on the stack. This union is sized to accommodate the largest possible message structure (e.g., DNSConfigMessage or AddressMessage). The function then reads a bytes_to_read value from the pipe and attempts to copy exactly that many bytes into the stack-allocated message buffer using ReadFromPipe. If an attacker can control the bytes_to_read value and make it larger than the actual size of the message union, a stack overflow occurs. While the presence of stack cookies/canaries (checked by __security_check_cookie at function exit) means a direct arbitrary write is difficult, overflowing the buffer will corrupt the canary, leading to a process crash. Tokarev notes that bypassing the canary without a memory read primitive is extremely hard, making this primarily a denial-of-service or crash-based LPE rather than a direct RCE vector.
Named Pipe Exploitation for LPE:
The crash aspect of the stack overflow is weaponized for LPE. The core idea is to exploit the named pipe's inherent trust model and Windows' behavior:
- A malicious DLL is crafted.
- This DLL is injected into the
OpenVPN daemonprocess (achieved later via RCE). - The malicious DLL sends an oversized packet through the inner named pipe to the
OpenVPN server, causing the server to crash due to the stack overflow. - After the
OpenVPN servercrashes, the malicious DLL recreates the well-knownOpenVPN/servicenamed pipe. - When a legitimate, unprivileged user later attempts to connect to the
OpenVPN service(e.g., by launching the GUI), they unknowingly connect to the attacker's malicious named pipe. - The attacker's DLL, impersonating the service, can then intercept
startup_dataand, if the connecting client is sufficiently privileged, execute arbitrary commands (e.g.,driver_communicator.exe) with the client's (potentiallySYSTEM) privileges.
Remote Code Execution (RCE) Chain:
Achieving RCE remotely requires a more elaborate chain:
- NLMv2 Hash Cracking: Remote access to Windows named pipes (via
net use \\endpoint\IPC$) typically requires authentication. Attackers can sniff NLMv2 hashes from network traffic using tools like Responder. These hashes, representing user credentials, can then be cracked. Tokarev demonstrated the efficiency of cloud platforms like vast.ai, which allow renting powerful GPU machines (e.g., 18 RTX 4090s for $85/hour). This setup can crack a 9-character NLMv2 password in less than 3 minutes, making robust password policies critical. - Remote SMB/IPC Access: With cracked credentials, an attacker can establish a remote connection to the target's
IPC$share. - Malicious Plugin Injection: OpenVPN supports plugins, which are DLLs exporting specific functions (e.g.,
OpenVPNPluginOpenV1,FuncV1) for custom logic like credential validation or event logging. The attacker configures their own OpenVPN setup to point to a malicious plugin located on an attacker-controlled SMB share. Using the remote IPC connection, the attacker passes this crafted configuration to the remote OpenVPN service. The remoteOpenVPN daemon, upon startup, attempts to load the plugin specified in the configuration. If the attacker's SMB share is configured to allow anonymous access (e.g.,Everyonehas read permissions), the daemon will load and execute the malicious plugin, granting RCE.
PPL Bypass with Kernel Primitives:
The final stage of the attack chain focuses on bypassing Protected Process Light (PPL). PPL, introduced in Windows 8.1, protects critical system processes (like wininit.exe, lsass.exe, csrss.exe) from termination or modification, even by processes running as SYSTEM. This protection is enforced through an internal PS_PROTECTION structure within the EPROCESS block of each process.
Once an attacker has achieved RCE and LPE, they can often gain arbitrary kernel read/write primitives, for example, by exploiting known vulnerabilities in third-party drivers (Bring Your Own Vulnerable Driver - BYOVD) or a 1-day/0-day in Windows (e.g., in appid.sys). With kernel read/write, the attacker can:
- Locate the
EPROCESSstructure of the target PPL-protected process (e.g.,wininit.exe). - Find the
PsProtectionfield within this structure. - Overwrite the values in
PsProtection(e.g.,Type,Signer,Level) to effectively disable PPL protection for that specific process. - Once protection is disabled, the attacker (even from a
SYSTEMprocess) can terminate or manipulate the previously protected process, allowing them to disable security software, hide rootkits, or perform other stealthy operations. This was demonstrated using WinDbg concepts to illustrate the memory overwrite.
Demo / Proof of Concept
▶ Watch: Using Yara rules to find 50 affected drivers (6:40)
Vladimir Tokarev’s presentation included several live demonstrations that progressively built up the attack chain, showcasing the practical feasibility of his findings.
1. Local Privilege Escalation (LPE) Demo:
The first demonstration focused on the local privilege escalation achieved by exploiting the stack overflow in the OpenVPN service and the named pipe impersonation.
- Setup: On the right side of the screen, the attacker’s machine ran the exploit code. On the left, a target Windows machine was shown.
- Execution: The exploit initiated by loading a malicious DLL into the
OpenVPN daemon. This DLL's primary function was to send a specially crafted, oversized message to the legitimateOpenVPN servervia the inner named pipe. This triggered the stack overflow, causing theOpenVPN serverprocess to crash. - Impersonation: Immediately after the crash, the malicious DLL, still running within the OpenVPN daemon, recreated the
OpenVPN/servicenamed pipe with the exact same name as the legitimate service. - Privilege Escalation: When a low-privileged user on the target machine subsequently attempted to connect to the OpenVPN service (e.g., by launching the OpenVPN GUI to start a VPN connection), they unknowingly connected to the attacker's impersonated named pipe. The attacker's DLL intercepted the connection, processed the
startup_data, and, by impersonating the connecting client, was able to execute a malicious application (e.g.,driver_communicator.exe) with the higher privileges of the client, potentially achieving SYSTEM-level access. The demo visually confirmed the elevated process on the left side, highlighting the successful LPE.
2. Remote Code Execution (RCE) Demo:
The second demonstration showcased the remote code execution vector, leveraging credential theft and malicious OpenVPN plugin loading.
- Setup: An attacker-controlled machine hosted an SMB share configured to allow anonymous access and contained a malicious OpenVPN plugin DLL.
- Execution: The attacker's exploit, running on their controlled machine, used previously obtained credentials (e.g., cracked NLMv2 hashes) to connect to the remote target's
IPC$share. Through this remote named pipe connection to theOpenVPN service, the exploit passed a specially crafted OpenVPN configuration. This configuration instructed the target'sOpenVPN daemonto load the malicious plugin from the attacker-controlled SMB share. - Impact: Upon loading, the malicious plugin executed arbitrary code on the remote endpoint. The demonstration visually confirmed this by showing the plugin dumping a large number of files onto the target machine's desktop, proving the RCE capability. This demo underscored the importance of securing SMB shares and robust password policies.
3. Full Chain RCE + LPE + Kernel Primitives + PPL Bypass Demo:
The final, most impactful demonstration combined all the previous elements into a full attack chain, culminating in the bypass of Protected Process Light (PPL).
- Execution Flow:
- The remote exploit connected to the target's
OpenVPN servicenamed pipe. - It executed the malicious plugin (Stage 1 & 2 successful, as shown in logs).
- This plugin then initiated the LPE logic, gaining higher privileges.
- With elevated privileges, the attacker leveraged a known vulnerability (e.g., in
appid.sysor a BYOVD scenario) to obtain arbitrary kernel read/write primitives. - Using these kernel primitives, the exploit then targeted a PPL-protected process, specifically
wininit.exe. It overwrote thePS_PROTECTIONstructure withinwininit.exe'sEPROCESSblock, effectively removing its PPL protection (Stage 3 & 4 successful, as shown in logs).
- Trigger: The final stages of the attack were triggered when an end-user on the target machine launched the OpenVPN GUI, which ran with highly elevated privileges and communicated with the now-compromised OpenVPN service.
- Outcome: The demonstration successfully illustrated how an attacker could move from initial remote access to full control, including the ability to disable Windows' most robust process protection mechanisms, enabling stealthy and persistent compromises. This highlighted the severe implications for system integrity and security software evasion.
Defensive Implications
▶ Watch: Confirming the bug in OpenVPN's tap-windows6 source code (8:15)
The vulnerabilities and attack chains presented by Vladimir Tokarev have significant implications for defenders. Implementing robust security measures is crucial to mitigate these types of advanced threats, especially given the widespread deployment of OpenVPN.
- Patch and Update OpenVPN Components:
- Ensure all OpenVPN clients, servers, and especially the TAP Windows driver (
TapWindows6) are updated to the latest patched versions. This is critical to address the integer overflow and any other discovered vulnerabilities. - Regularly monitor OpenVPN's security advisories and apply updates promptly.
- Strengthen Password Policies:
- Given the demonstrated ease and speed of NLMv2 hash cracking using cloud GPU platforms (e.g., vast.ai cracking a 9-character password in under 3 minutes), enforcing strong, complex, and lengthy passwords is paramount.
- Implement multi-factor authentication (MFA) wherever possible to add an extra layer of defense against credential theft.
- Restrict SMB/IPC Access and Anonymous Shares:
- Limit remote access to SMB shares and IPC$ named pipes to only necessary accounts and IP ranges.
- Never allow anonymous access to SMB shares, especially those that could host executable content or configuration files. The RCE demo explicitly required anonymous access to the attacker's share.
- Implement strict firewall rules to restrict SMB traffic (ports 139, 445) to trusted networks only.
- Monitor Named Pipe Activity:
- Implement advanced monitoring for the creation and access patterns of critical named pipes, particularly
OpenVPN/serviceand other system-level IPC mechanisms. - Detect anomalous named pipe creation (e.g., a non-SYSTEM process creating the
OpenVPN/servicepipe) or unusual message sizes/contents indicative of the stack overflow exploit.
- Secure OpenVPN Plugin Loading:
- Enforce strict controls over where OpenVPN plugins can be loaded from. Ideally, plugins should be signed and loaded only from trusted, local directories.
- Audit OpenVPN configurations for directives that load plugins from remote or untrusted locations.
- Implement Application Control and Whitelisting:
- Use application control solutions (e.g., Windows Defender Application Control, AppLocker) to restrict which executables and DLLs can run on endpoints. This can prevent the execution of malicious OpenVPN plugins or arbitrary executables launched via LPE.
- Monitor for Vulnerable Drivers and Kernel Integrity:
- Regularly scan systems for known vulnerable drivers (BYOVD) that could be exploited to gain kernel read/write primitives.
- Utilize endpoint detection and response (EDR) solutions that can detect kernel-level attacks, including attempts to modify critical kernel structures like
PS_PROTECTIONto bypass PPL. - Ensure HVCI (Hypervisor-Enforced Code Integrity) and other kernel mitigations are enabled and properly configured.
- Educate Users:
- Educate users about the importance of strong passwords and the risks associated with connecting to untrusted networks or VPN services.
- Emphasize the use of official and verified VPN clients and configurations.
Key Takeaways
- One Bug, Global Impact: A single, seemingly minor integer overflow vulnerability in a widely used component like OpenVPN's TAP driver can have widespread implications across countless VPN services and endpoints due to shared codebases.
- Named Pipes are Critical Attack Surface: Windows named pipes, fundamental for inter-process communication, present a significant attack surface for local privilege escalation, service impersonation, and denial-of-service, especially when combined with stack overflow vulnerabilities.
- Reconnaissance and Credential Theft are Foundational: Effective remote code execution often hinges on robust reconnaissance (OSINT tools like Shodan, VirusTotal, Yara) and successful credential theft (e.g., NLMv2 hash cracking), highlighting the need for strong password policies and network monitoring.
- Cloud Cracking Lowers Barriers: Cloud computing platforms like vast.ai dramatically reduce the cost and technical barrier for high-speed hash cracking, making advanced credential attacks more accessible and underscoring the urgency for organizations to implement strong, long passwords and MFA.
- Advanced Mitigations are Not Impenetrable: Even sophisticated kernel-level protections like Protected Process Light (PPL) can be bypassed by attackers who achieve arbitrary kernel read/write primitives, demonstrating the continuous cat-and-mouse game between defenders and determined adversaries.
- Full Attack Chains are the Reality: Modern attacks are rarely single-vulnerability exploits; they often involve chaining multiple, seemingly disparate vulnerabilities and techniques (RCE, LPE, kernel exploits, PPL bypass) to achieve their objectives.
About the Speaker(s)
Vladimir Tokarev is a Senior Security Researcher at Microsoft. He is recognized for his significant contributions to security research, including his work with the Quotesis framework. Tokarev has also made notable discoveries by identifying and reporting bugs in the Windows driver of SonicWall tools, demonstrating his expertise in driver-level vulnerabilities and system-level security. His research consistently highlights advanced reconnaissance techniques and their application in uncovering critical security flaws in widely used software and infrastructure.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Tokarev delivers a complete, multi-stage exploit chain against OpenVPN's Windows stack — integer overflow in TapWindows6, stack overflow in the service IPC handler, named pipe impersonation for LPE, remote plugin injection for RCE, and PPL bypass via kernel primitives. The OSINT angle (Yara + VirusTotal to find 50+ affected drivers) is a genuinely clever methodology that elevates this beyond a single CVE drop. Solid technical depth with live demos that actually prove the chain works end-to-end.
Heather Calloway (CISO) — WEAK
Technically serious research — a full RCE-to-PPL-bypass chain against OpenVPN is not a minor finding — but the presentation never surfaces past the exploit layer into institutional consequence. The defensive section lists eight generic mitigations that read like a security checklist template, and no one responsible for procurement, architecture governance, or VPN vendor risk management gets told what decision to make.