CVE-2026-82325
6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OpenVPN | ovpn-dco-win | 2.5.0 <= 2.8.6 | affected |
Weaknesses
- CWE-416: CWE-416 Use after free
- CWE-415: CWE-415 Double free
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.