Low severity3.3NVD Advisory· Published Jan 15, 2025· Updated Jun 17, 2026
CVE-2024-5198
CVE-2024-5198
Description
OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
Affected products
4cpe:2.3:a:openvpn:ovpn-dco-win:1.1.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:openvpn:ovpn-dco-win:1.1.1:*:*:*:*:*:*:*
- (no CPE)range: =1.1.1
- (no CPE)range: 1.1.1
Patches
Vulnerability mechanics
References
1- community.openvpn.net/openvpn/wiki/CVE-2024-5198nvdVendor Advisory
News mentions
0No linked articles in our index yet.