Impact
The flaw allows a local authenticated user on Windows to cause a denial of service in OpenVPN by setting a NULL DACL on named IPC objects. When the access control list is improperly cleared, the OpenVPN process can hang or crash, taking the VPN service offline and preventing legitimate users from connecting. The impact is strictly on availability; there is no direct compromise of confidentiality or integrity reported.
Affected Systems
OpenVPN releases 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows operating systems are affected. Only installations of these versions that permit local authentication are vulnerable.
Risk and Exploitability
The CVSS score of 1.8 and an EPSS score of less than 1% indicate a low overall risk and a very small probability of exploitation. The flaw does not appear in CISA’s KEV catalog. Exploitation requires a local authenticated user; the attack vector is local, and the adversary would need to be able to execute actions on the target machine to trigger the null DACL creation and cause the service to fail.
OpenCVE Enrichment