Executive brief
OpenVPN's Windows Interactive Service contains a buffer size calculation error that can be exploited by authenticated local users. An attacker with local system access could cause memory corruption or leak sensitive information through specially crafted NRPT inputs, potentially compromising system stability or exposing confidential data.
Technical details
The vulnerability is a buffer size calculation error in OpenVPN's Windows Interactive Service component. It affects versions 2.7_alpha1 through 2.7.6 and allows local authenticated users to trigger memory corruption or information disclosure by submitting specially crafted NRPT (Name Resolution Policy Table) inputs. The vulnerability requires local authentication and direct access to the affected service. An attacker can cause memory corruption leading to denial of service or read adjacent memory to disclose sensitive information.
Affected products
- OpenVPN OpenVPN 2.7_alpha1 through 2.7.6
Timeline
- 2026-09-07: disclosed