# CVE-2024-5198: OpenVPN ovpn-dco for Windows Version 1.1.1 Vulnerability
+
# CVE-2024-5198: OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
-
OpenVPN ovpn-dco for Windows version 1.1.1 is vulnerable to a security issue where an unprivileged local attacker can send I/O control messages with invalid data to the driver. This results in a NULL pointer dereference, leading to a system halt.
+
Affected versions: ovpn-dco Windows driver 1.1.1, OpenVPN 2.6.10-I002 Windows client (older and newer versions of the driver and Windows client are not affected)
-
**Affected versions:**
-
- ovpn-dco Windows driver 1.1.1
-
- OpenVPN 2.6.10-I002 Windows client
-
-
Note: Only the specified versions are affected. Older and newer versions of the driver and Windows client are not affected.