CVE-2025-50054

Severity CVSS v4.0:
Pending analysis
Type:
CWE-122 Heap-based Buffer Overflow
Publication date:
20/06/2025
Last modified:
21/08/2025

Description

Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openvpn:ovpn-dco-win:*:*:*:*:*:*:*:* 1.3.0 (including)
cpe:2.3:a:openvpn:ovpn-dco-win:*:*:*:*:*:*:*:* 2.4.0 (including) 2.5.8 (including)