#VU82576 Externally Controlled Reference to a Resource in Another Sphere in WireGuard for Windows - CVE-2023-35838

 

#VU82576 Externally Controlled Reference to a Resource in Another Sphere in WireGuard for Windows - CVE-2023-35838

Published: October 31, 2023


Vulnerability identifier: #VU82576
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-35838
CWE-ID: CWE-610
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
WireGuard for Windows
Software vendor:
WireGuard

Description

The vulnerability allows a remote attacker to block access to certain resources.

The vulnerability exists due to the way WireGuard handles non-RFC1918 IP addresses. A remote attacker can trick the victim into blocking IP traffic to selected IP addresses and services even while the VPN is enabled.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links