Externally Controlled Reference to a Resource in Another Sphere in WireGuard for Windows - CVE-2023-35838

 

Externally Controlled Reference to a Resource in Another Sphere in WireGuard for Windows - CVE-2023-35838

Published: October 31, 2023


Vulnerability identifier: #VU82576
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-35838
CWE-ID: CWE-610
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to block access to certain resources.

The vulnerability exists due to the way WireGuard handles non-RFC1918 IP addresses. A remote attacker can trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled.


Affected software

WireGuard for Windows

How to mitigate CVE-2023-35838

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins