CVE-2024-1305: Openvpn Tap-WINDOWS6
Critical severity, CVSS 9.8. EPSS: 15.4% chance of exploitation in the next 30 days.
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space
Affected products
- Openvpn Tap-WINDOWS6: up to and including 9.26.0
Published 2024-07-08. Last modified 2026-06-17.