OpenVPN ovpn-dco-win Buffer Overflow Vulnerability Leading to Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in OpenVPN ovpn-dco-win versions through 1.3.0 and versions through 2.5.8. This vulnerability allows a local user process to send an oversized control message buffer to the kernel driver, causing a system crash.

Impact

Exploitation of this vulnerability leads to a system crash, causing a denial-of-service condition.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.