CVE-2024-5198: OpenVPN ovpn-dco for Windows Version 1.1.1 Vulnerability
OpenVPN ovpn-dco for Windows version 1.1.1 is vulnerable to a security issue where an unprivileged local attacker can send I/O control messages with invalid data to the driver. This results in a NULL pointer dereference, leading to a system halt.
Affected versions:
- ovpn-dco Windows driver 1.1.1
- OpenVPN 2.6.10-I002 Windows client
Note: Only the specified versions are affected. Older and newer versions of the driver and Windows client are not affected.
References
- GitHub PR: https://github.com/OpenVPN/ovpn-dco-win/pull/70
- CVE record: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5198
- Reported-By: Lukas Jokubauskas lukas.jokubauskas@nordsec.com
