Impact
An incorrect buffer size calculation in the Windows Interactive Service of OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information when crafted NRPT inputs are processed. The exploitation does not require network exposure and is limited to the NRPT handling component, resulting in potential compromise of local system integrity or confidentiality.
Affected Systems
OpenVPN’s Windows Interactive Service component is impacted in releases 2.7_alpha1 to 2.7.6. Users running these versions on Windows hosts are vulnerable if the Interactive Service is enabled and NRPT inputs are accepted.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. The EPSS score is less than 1%, implying a low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA KEV. The attack vector requires local authentication, meaning only users who have logged into the Windows system can trigger the flaw. Absent a public exploit, the risk remains limited to individuals or processes with local access.
OpenCVE Enrichment