Executive brief
OpenVPN is a widely-used VPN client used to establish secure remote connections to corporate networks and services. A flaw in the Windows tap-windows6 driver allows remote attackers to trigger an out-of-bounds memory write via specially crafted domain search configuration, potentially leading to denial of service or code execution on affected Windows systems.
Technical details
The vulnerability is an out-of-bounds write condition in the tap-windows6 driver component used by OpenVPN on Windows. The flaw is triggered via crafted DOMAIN-SEARCH entries in OpenVPN configuration, allowing an attacker on the network to send specially crafted packets that exploit insufficient input validation. The attack is network-reachable and does not require prior authentication. Successful exploitation could result in denial of service (driver crash) or potentially arbitrary code execution with system privileges, depending on memory layout and exploitation technique. Versions 2.5.0 through 2.7.6 are affected; patched versions are expected from the OpenVPN project.
Affected products
- OpenVPN OpenVPN 2.5.0 through 2.7.6
Timeline
- 2026-09-07: disclosed