Impact
A use‑after‑free bug exists in the OpenVPN ovpn‑dco‑win driver, allowing a local authenticated user to crash the system by sending specially crafted control messages. The flaw results in an integrity breakdown of shared memory without granting arbitrary code execution, leading strictly to a denial of service outcome. This weakness is rooted in improper memory management and double‑free logic, identified as CWE‑415 and CWE‑416.
Affected Systems
The vulnerability affects the OpenVPN Windows driver known as ovpn‑dco‑win, version range 2.5.0 through 2.8.6. Only systems running these driver builds and operating with local user credentials are at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity, and the lack of an EPSS score means availability of recent exploit data is unknown. The issue is not listed in the KEV catalog and requires local authentication to trigger. An attacker would need access to the target machine’s local control interface and would craft malicious messages to trigger the use‑after‑free and cause a crash.
OpenCVE Enrichment