Remote DNS State Pollution in OpenVPN Windows Interactive Service
CVE-2026-13379
5.1MEDIUM
What is CVE-2026-13379?
The Windows interactive service in OpenVPN versions 2.7_alpha1 through 2.7.4 is susceptible to a vulnerability that allows remote attackers to manipulate DNS resolutions. By exploiting crafted search domains during the disconnection process, attackers can not only cause persistent DNS state pollution but may also induce a service crash. This could lead to a disruption in connectivity and a potential compromise of sensitive data. It is crucial for users of affected versions to patch their installations promptly to mitigate these risks.
Affected Version(s)
OpenVPN Windows 2.7_alpha1 <= 2.7.4