#VU82576 Externally Controlled Reference to a Resource in Another Sphere in WireGuard for Windows - CVE-2023-35838
Published: October 31, 2023
Vulnerability identifier: #VU82576
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-35838
CWE-ID: CWE-610
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerable software:
WireGuard for Windows
WireGuard for Windows
Software vendor:
WireGuard
WireGuard
Description
The vulnerability allows a remote attacker to block access to certain resources.
The vulnerability exists due to the way WireGuard handles non-RFC1918 IP addresses. A remote attacker can trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled.
Remediation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.