VendorsOpenVPNovpn-dco-winall versions
Vulnerabilities

OpenVPN ovpn-dco-win (OpenVPN Data Channel Offload for Windows)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-11604
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).
Published 2026-06-10 · Analyzed
6.5EPSS 0.003
CVE-2025-50054
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash
Published 2025-06-20 · Analyzed
5.5EPSS 0.002
CVE-2024-5198
OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
Published 2025-01-15 · Analyzed
3.3EPSS 0.001