Externally Controlled Reference to a Resource in Another Sphere in WireGuard for Windows - CVE-2023-35838
Published: October 31, 2023
Vulnerability identifier: #VU82576
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35838
CWE-ID: CWE-610
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to block access to certain resources.
The vulnerability exists due to the way WireGuard handles non-RFC1918 IP addresses. A remote attacker can trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled.
Affected software
WireGuard for Windows
How to mitigate CVE-2023-35838
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.