CVE-2024-5198: OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

Affected versions: ovpn-dco Windows driver 1.1.1, OpenVPN 2.6.10-I002 Windows client (older and newer versions of the driver and Windows client are not affected)

References