CVE-2026-82312
Public on 2026-09-05
Modified on 2026-09-05
Description
OpenVPN 2.x on Windows created the --service exit event and the netsh.exe guard semaphore with a NULL DACL, which allows a local user to interfere with other users' openvpn processes by blocking the netsh semaphore or by signalling the exit event, leading to a local denial of service. Only setups not using the interactive service, or using the automatic service to start and stop openvpn, are affected. OpenVPN version 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 are affected. This is fixed in version 2.7.7.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2023 | openvpn | Not Affected | ||
| Amazon Linux 2027 Preview | openvpn | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.5 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |