First published: Wed Jan 15 2025(Updated: )
OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
Credit: security@openvpn.net
Affected Software | Affected Version | How to fix |
---|---|---|
OpenVPN |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-5198 is classified as a high severity vulnerability due to its potential to cause a system halt.
To fix CVE-2024-5198, upgrade to the latest version of OpenVPN ovpn-dco where the vulnerability has been patched.
CVE-2024-5198 affects users of OpenVPN ovpn-dco for Windows version 1.1.1.
CVE-2024-5198 can lead to a NULL pointer dereference resulting in a system halt, disrupting normal operations.
While exploit code for CVE-2024-5198 has not been publicly disclosed, its impact is significant enough to warrant immediate attention from system administrators.