
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13751 is a local denial-of-service vulnerability in the OpenVPN interactive service agent on Windows. A local authenticated user can connect to the service and trigger an error condition that crashes the service, resulting in a denial of service. The vulnerability affects OpenVPN Community Edition versions 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2, exclusively on Windows. It was disclosed on December 3, 2025, with the CVE description refined on December 12, 2025. The CVSS v3.1 base score is 5.5 (Medium) (OpenVPN Advisory, NVD).
The vulnerability is rooted in three CWE classifications: CWE-770 (Allocation of Resources Without Limits or Throttling), CWE-775 (Missing Release of File Descriptor or Handle after Effective Lifetime), and CWE-841 (Improper Enforcement of Behavioral Workflow). The interactive service agent — a Windows service component that facilitates communication between the OpenVPN GUI and the privileged service — fails to properly handle certain error conditions triggered by a locally authenticated user connecting to it, likely due to improper resource cleanup or workflow enforcement. The attack vector is local, requires low privileges, and no user interaction beyond the attacker's own actions is needed. No public proof-of-concept code has been identified (OpenVPN Advisory, NVD).
Successful exploitation results in a local denial of service, crashing the OpenVPN interactive service agent on the affected Windows host. This would disrupt VPN connectivity for all users relying on the service, potentially interrupting secure remote access. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. The scope is confined to the local system and does not enable lateral movement or data exfiltration (NVD, OpenVPN Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-13751. The EPSS score is extremely low at approximately 0.013%, reflecting minimal likelihood of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The local attack surface and authentication requirement significantly limit the practical exploitability of this flaw (NVD, OpenVPN Advisory).
openvpnserv.exe or similar) is running via Windows Services or Task Manager.openvpnserv.exe); Service Control Manager events (Event ID 7034 or 7031) indicating the service terminated unexpectedly.openvpnserv.exe process after it was previously running; repeated service restart attempts visible in the Windows Event Log..dmp) generated in the Windows error reporting directory associated with openvpnserv.exe.OpenVPN has released version 2.6.17 as the patched stable release addressing this vulnerability; users of the 2.7 pre-release series should upgrade to 2.7_rc3 or later when available. Administrators should prioritize upgrading all Windows deployments of OpenVPN Community Edition from affected versions (2.5.0–2.6.16, 2.7_alpha1–2.7_rc2) to 2.6.17 or newer. As a temporary workaround, restricting local user access to the OpenVPN interactive service via Windows access controls may reduce exposure, though upgrading is the recommended solution (OpenVPN Advisory, OpenVPN Announce).
Security news outlets including CyberSecurityNews, GBHackers, and CyberNoz covered this vulnerability as part of broader reporting on a set of OpenVPN security fixes released in late 2025, which also included an HMAC bypass and buffer over-read issue. The Hacker News included it in their weekly security recap. Community sentiment reflects that the local-only, authenticated attack surface limits the urgency, though the patch is recommended as part of routine maintenance (CyberSecurityNews, GBHackers, The Hacker News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."