CVE-2025-50054: Openvpn Ovpn-Dco-Win

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash

Affected products

  • Openvpn Ovpn-Dco-Win: up to and including 1.3.0; from 2.4.0, up to and including 2.5.8

Published 2025-06-20. Last modified 2026-06-17.