Impact
An incorrect buffer size calculation in the Windows Interactive Service of OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to trigger memory corruption or expose sensitive data. The flaw is limited to NRPT handling, which can corrupt application memory or leak data to the attacker when supplied with specially crafted inputs. The primary consequence is potential compromise of local system integrity or confidentiality depending on the information revealed.
Affected Systems
The vulnerability affects the OpenVPN product, specifically the Windows Interactive Service component included in the 2.7_alpha1 to 2.7.6 releases. Users running these versions on Windows platforms are susceptible if the Interactive Service is enabled and NRPT inputs are accepted.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity. The attack requires local authentication, meaning it is limited to users who have logged into the Windows host. No public exploit is known, and the vulnerability is not listed in CISA KEV. Since EPSS is unavailable, exploitation likelihood cannot be precisely quantified, but the moderate score suggests that if an attacker can gain local access, the risk of successful exploitation is non‑negligible.
OpenCVE Enrichment