VYPR
Low severity3.3NVD Advisory· Published Jan 15, 2025· Updated Jun 17, 2026

CVE-2024-5198

CVE-2024-5198

Description

OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.

Affected products

4
  • cpe:2.3:a:openvpn:ovpn-dco-win:1.1.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:openvpn:ovpn-dco-win:1.1.1:*:*:*:*:*:*:*
    • (no CPE)range: =1.1.1
    • (no CPE)range: 1.1.1
  • OpenVPN/OpenVPNcpe-rescue
    Range: 2.6.10-I002

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.