CVE-2022-41924

Description from NVD

A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bound to a local TCP socket, and communicated with the Windows client GUI in cleartext with no Host header verification. This allowed an attacker-controlled website visited by the node to rebind DNS to an attacker-controlled DNS server, and then make local API requests in the client, including changing the coordination server to an attacker-controlled coordination server. An attacker-controlled coordination server can send malicious URL responses to the client, including pushing executables or installing an SMB share. These allow the attacker to remotely execute code on the node. All Windows clients prior to version v.1.32.3 are affected. If you are running Tailscale on Windows, upgrade to v1.32.3 or later to remediate the issue.

Information Acquisition Date:2022/12/01
CVSS 2.0: 0.0 None CVSS 3.x: 9.8 CRITICAL

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD References

 http://hsqldb.org/doc/2.0/guide/sqlroutines-chapt.html#src_jrt_access_control
     source:MISC
     tags:Technical Description    Third Party Advisory    
 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50212#c7
     source:MISC
     tags:Mailing List    Third Party Advisory    
 [debian-lts-announce] 20221210 [SECURITY] [DLA 3234-1] hsqldb security update
     source:MLIST
     tags:

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag: BIND(16 tweets) Java(2 tweets) VPN(1 tweets) Windows(31 tweets) Wordpress(1 tweets)



List of frequently cited URLs

URLNum of Times Referred to
https://cvetrends.com50
https://emily.id.au/tailscale26
https://news.ycombinator.com/item?id=3369588611
https://tailscale.com/security-bulletins/#ts-2022-00410

▼ Show Information from Twitter(98)


List of frequently cited URLs

URLNum of Times Referred to
cvetrends.com50
emily.id.au26
news.ycombinator.com11
tailscale.com10

▼ Show Information from Twitter(98)


GitHub Search Results: Up to 10
NameURL
No Data

GitHub Search Results: Up to 10
NameURL
No Data

2022/12/12 Score : 0
Added Har-sia Database : 2022/11/22
Last Modified : 2022/12/12
Highest Scored Date : 2022/11/22
Highest Score : 52