CVE-2025-50054: Openvpn Ovpn-Dco-Win
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash
Affected products
- Openvpn Ovpn-Dco-Win: up to and including 1.3.0; from 2.4.0, up to and including 2.5.8
Published 2025-06-20. Last modified 2026-06-17.