OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
2025-01-15T13:15:15.090
2025-06-10T16:12:09.340
Analyzed
CVSSv3.1: 3.3 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openvpn | ovpn-dco-win | 1.1.1 | Yes |