Executive brief
OpenVPN's ovpn-dco-win driver contains a use-after-free memory vulnerability that allows authenticated local users to trigger a system crash. This could disrupt VPN connectivity for affected systems and potentially be exploited to escalate privileges or execute code, though the immediate impact is denial of service.
Technical details
A use-after-free vulnerability exists in the OpenVPN ovpn-dco-win driver versions 2.5.0 through 2.8.6 in the handling of control messages. An authenticated local attacker can craft specially formed control messages to trigger access to memory that has already been freed, causing a kernel panic or system crash. The attack requires local authentication and the ability to send crafted control messages to the driver. Use-after-free flaws can potentially be escalated beyond denial of service, though current evidence indicates the primary impact is system crash.
Affected products
- OpenVPN ovpn-dco-win 2.5.0 through 2.8.6
Timeline
- 2026-09-07: disclosed