CVE-2026-82325: Use After Free
Published Sep 7, 2026
·Updated
A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages
Affected Software
1 affected component
OpenVPN ovpn-dco-win driver>=2.5.0<=2.8.6
Event History
Sep 7, 2026
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Exploitation requires local authenticated access to a Windows system with an affected OpenVPN ovpn-dco-win driver installed. The stated impact is a system crash.
2
What does an attacker need to do to trigger the vulnerability?
An attacker needs to send crafted control messages to the affected driver. The available information does not indicate that remote or unauthenticated exploitation is possible.
3
Which driver versions are affected?
OpenVPN ovpn-dco-win driver versions 2.5.0 through 2.8.6 are affected.