Use-After-Free Vulnerability in OpenVPN OVPN-DCO-WIN Driver by OpenVPN
CVE-2026-82325

6.8MEDIUM

Key Information:

Vendor

Openvpn

Vendor
CVE Published:
7 September 2026

What is CVE-2026-82325?

A use-after-free vulnerability exists in the OpenVPN ovpn-dco-win driver from versions 2.5.0 to 2.8.6. This issue allows local authenticated users to exploit crafted control messages, potentially leading to system crashes. It's critical for users to update affected versions to ensure system stability and security. For more details, refer to the vendor advisory.

Affected Version(s)

ovpn-dco-win Windows 2.5.0 <= 2.8.6

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.