← Back to browse · API

CVE-2024-1305

Severity
CRITICAL
CVSS
9.8
EPSS
0.15379
Risk score
44.58
CISA KEV
No
PoC
No
Published
2024-07-08
Modified
2024-08-23
First seen
2026-08-07
Aliases
EUVD-2024-17065, GHSA-FV4P-HRVC-C34G
Products
OpenVPN:OpenVPN-GUI 2.6.9 and earlier, OpenVPN:tap-windows6 9.26 or earlier
Sources
euvd EUVD-2024-17065

Description

tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space

References