CVE-2025-13751 - Windows/interactive service: fix erroneous exit on error that could be used by a local Windows users to achieve a local denial-of-service
Windows/interactive service: fix bug where the interactive service would error-exit in certain error conditions instead of just logging the fact and continuing. After the error-exit, OpenVPN connections will no longer work until the service is restarted (or the system rebooted). This can be triggered by any authenticated local user, and has thus been classified as a "local denial of service" attack.
OpenVPN version 2.6.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 are affected. This is fixed in version 2.6.17 and 2.7_rc3.
CVE Record: CVE-2025-13751
Github: OpenVPN/openvpn-private-issues#95
Release notes: openvpn-2.7_rc3 openvpn-2.6.17
Reported by: Lev Stipakov lev@openvpn.net
