CVE-2024-1305
Estado: AnalizadaCrítica (9.8)—
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 15%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-190
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-1305",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-1305",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-08-21T00:00:00+00:00"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security@openvpn.net",
"affectedData": [
{
"vendor": "OpenVPN",
"product": "tap-windows6",
"versions": [
{
"status": "affected",
"version": "9.26 or earlier"
}
],
"platforms": [
"Windows"
],
"defaultStatus": "unaffected"
},
{
"vendor": "OpenVPN",
"modules": [
"tap-windows6"
],
"product": "OpenVPN-GUI",
"versions": [
{
"status": "affected",
"version": "2.6.9 and earlier"
}
],
"platforms": [
"Windows"
],
"defaultStatus": "unaffected"
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:openvpn:openvpn_gui:*:*:*:*:*:*:*:*"
],
"vendor": "openvpn",
"product": "openvpn_gui",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "2.6.9"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:openvpn:tap_windows6:*:*:*:*:*:*:*:*"
],
"vendor": "openvpn",
"product": "tap_windows6",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "9.26"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-07-08T18:15:07.150",
"references": [
{
"url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-1305",
"tags": [
"Vendor Advisory"
],
"source": "security@openvpn.net"
},
{
"url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html",
"tags": [
"Mailing List",
"Release Notes"
],
"source": "security@openvpn.net"
},
{
"url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-1305",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html",
"tags": [
"Mailing List",
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@openvpn.net",
"description": [
{
"lang": "en",
"value": "CWE-190"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "tap-windows6 driver version 9.26 and earlier does not properly \ncheck the size data of incomming write operations which an attacker can \nuse to overflow memory buffers, resulting in a bug check and potentially\n arbitrary code execution in kernel space"
},
{
"lang": "es",
"value": "La versión 9.26 y anteriores del controlador tap-windows6 no verifica correctamente los datos de tamaño de las operaciones de escritura entrantes que un atacante puede usar para desbordar los búfers de memoria, lo que resulta en una verificación de errores y la ejecución de código potencialmente arbitrario en el espacio del kernel."
}
],
"lastModified": "2026-06-17T07:03:56.383",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openvpn:tap-windows6:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1361B991-0259-40EC-89A2-06B591C84F5C",
"versionEndIncluding": "9.26.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@openvpn.net"
}