CVE-2024-5198

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Jan 15, 2025
CWE ID 270

Summary

CVE-2024-5198 is a newly disclosed vulnerability affecting the OpenVPN ovpn-dco driver for Windows version 1.1.1. An unprivileged local attacker can exploit this issue by sending invalid I/O control messages to the driver, leading to a NULL pointer dereference. The consequence of this vulnerability is a system halt. This vulnerability poses a significant risk to systems running the affected version of OpenVPN ovpn-dco and requires immediate attention from system administrators for patching or mitigation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share