Incorrect permission assignment for critical resource in OpenVPN Server - CVE-2026-82312
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to incorrect permission assignment for critical resources in the Windows service exit event and netsh.exe guard semaphore when OpenVPN creates system objects with a NULL DACL. A local user can block the netsh semaphore or send events to cause a denial of service.
Only setups not using the interactive service, or using the automatic service to start or stop OpenVPN, are affected.