Description
OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
Published: 2026-09-07
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-Bounds Write
Action: Assess
AI Analysis

Impact

OpenVPN versions 2.5.0 through 2.7.6 on Windows, when running the tap-windows6 driver, contain a memory‑corruption flaw that can be triggered by specially crafted DOMAIN-SEARCH entries in configuration files. The flaw permits an out-of-bounds write that may corrupt stack or heap memory, leading to a program crash or, if further exploited, unintended code execution.

Affected Systems

Systems running any OpenVPN release from 2.5.0 to 2.7.6 inclusive on Windows with the tap-windows6 driver are affected. These installations use a TAP interface on a Windows operating system.

Risk and Exploitability

The CVSS score of 2.3 classifies the vulnerability as low severity while the EPSS score of < 1% indicates a very low likelihood of exploitation in the wild; the flaw is not listed in the CISA KEV catalog. Attackers would need to supply a malicious configuration file containing crafted DOMAIN-SEARCH entries, implying a local or privileged threat vector. This inference is based on the fact that the flaw is triggered by configuration data rather than a network‑exposed input. Given the low severity and low exploitation probability, the overall risk remains limited, but the flaw can still result in denial of service if the configuration is compromised.

Generated by OpenCVE AI on September 7, 2026 at 15:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenVPN to the latest stable release that includes the tap‑windows6 driver fix.
  • - If upgrading is not immediately possible, audit all OpenVPN configuration files and remove or sanitize any DOMAIN-SEARCH entries that are unnecessary or suspicious.
  • - Consider disabling the tap‑windows6 driver or switching to a non‑vulnerable TAP driver; alternatively run OpenVPN without a network TAP interface if feasible.

Generated by OpenCVE AI on September 7, 2026 at 15:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title OpenVPN Windows TAP-Windows6 Out-of-Bounds Write via DOMAIN-SEARCH entries openvpn: OpenVPN: Out-of-bounds write via crafted DOMAIN-SEARCH entries
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}

threat_severity

Low


Mon, 07 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Title OpenVPN Windows TAP-Windows6 Out-of-Bounds Write via DOMAIN-SEARCH entries

Mon, 07 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn
Vendors & Products Openvpn
Openvpn openvpn

Mon, 07 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries
Weaknesses CWE-121
CWE-193
CWE-787
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2026-09-08T14:55:10.107Z

Reserved: 2026-08-27T11:45:58.319Z

Link: CVE-2026-81738

cve-icon Vulnrichment

Updated: 2026-09-08T14:55:04.969Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-07T08:17:13.270

Modified: 2026-09-08T19:07:52.113

Link: CVE-2026-81738

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-07T07:32:20Z

Links: CVE-2026-81738 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:45:17Z

Weaknesses