CVE-2026-82312

Public on 2026-09-05
Modified on 2026-09-05
Description
OpenVPN 2.x on Windows created the --service exit event and the netsh.exe guard semaphore with a NULL DACL, which allows a local user to interfere with other users' openvpn processes by blocking the netsh semaphore or by signalling the exit event, leading to a local denial of service. Only setups not using the interactive service, or using the automatic service to start and stop openvpn, are affected. OpenVPN version 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 are affected. This is fixed in version 2.7.7.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 openvpn Not Affected
Amazon Linux 2027 Preview openvpn Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H