OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://community.openvpn.net/openvpn/wiki/CVE-2024-5198 | vendor advisory |