Impact
OpenVPN versions 2.5.0 through 2.7.6 on Windows, when running the tap-windows6 driver, contain a memory‑corruption flaw that can be triggered by specially crafted DOMAIN-SEARCH entries in configuration files. The flaw permits an out-of-bounds write that may corrupt stack or heap memory, leading to a program crash or, if further exploited, unintended code execution.
Affected Systems
Systems running any OpenVPN release from 2.5.0 to 2.7.6 inclusive on Windows with the tap-windows6 driver are affected. These installations use a TAP interface on a Windows operating system.
Risk and Exploitability
The CVSS score of 2.3 classifies the vulnerability as low severity while the EPSS score of < 1% indicates a very low likelihood of exploitation in the wild; the flaw is not listed in the CISA KEV catalog. Attackers would need to supply a malicious configuration file containing crafted DOMAIN-SEARCH entries, implying a local or privileged threat vector. This inference is based on the fact that the flaw is triggered by configuration data rather than a network‑exposed input. Given the low severity and low exploitation probability, the overall risk remains limited, but the flaw can still result in denial of service if the configuration is compromised.
OpenCVE Enrichment