Impact
The Windows interactive service in OpenVPN versions 2.7_alpha1 through 2.7.4 can be exploited by remote attackers to trigger a persistent DNS state pollution or cause the service to crash when a disconnect occurs and a crafted search domain is processed. The vulnerability involves improper bounds checking and use‑after‑free errors (CWE-125 and CWE-142). A successful exploitation may degrade network reliability by corrupting DNS resolution or render the OpenVPN client unusable, but does not provide arbitrary code execution or privileged escalation.
Affected Systems
Affected systems include the OpenVPN Windows application in the 2.7 series, specifically versions 2.7_alpha1 up to 2.7.4. The problem is tied to the interactive service component that runs on Windows during disconnection events.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1% suggests a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Because the exploit requires an attacker to cause a controlled disconnect with a crafted search domain, the attack vector is likely remote network or DNS manipulation. No privileged escalation is required, and the vulnerability does not allow remote code execution. The exploitation conditions are relatively specific, which may limit real‑world usage, but the moderate CVSS and lack of mitigation in the affected releases suggest a non‑negligible risk for environments running these versions.
OpenCVE Enrichment