tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space
https://www.cisa.gov/news-events/ics-advisories/icsa-25-072-10
https://thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html
https://www.microsoft.com/en-us/security/blog/2024/08/08/chained-for-attack-openvpn-vulnerabilities-discovered-leading-to-rce-and-lpe/
https://www.mail-archive.com/[email protected]/msg07534.html
https://community.openvpn.net/openvpn/wiki/CVE-2024-1305
Source: Mitre, NVD
Published: 2024-07-08
Updated: 2025-08-22
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00464