« Volver al listado

CVE-2024-1305

Estado: AnalizadaCrítica (9.8)—

tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-1305",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-1305",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-21T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@openvpn.net",
      "affectedData": [
        {
          "vendor": "OpenVPN",
          "product": "tap-windows6",
          "versions": [
            {
              "status": "affected",
              "version": "9.26 or earlier"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "OpenVPN",
          "modules": [
            "tap-windows6"
          ],
          "product": "OpenVPN-GUI",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.9 and earlier"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:openvpn:openvpn_gui:*:*:*:*:*:*:*:*"
          ],
          "vendor": "openvpn",
          "product": "openvpn_gui",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "2.6.9"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:openvpn:tap_windows6:*:*:*:*:*:*:*:*"
          ],
          "vendor": "openvpn",
          "product": "tap_windows6",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "9.26"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-07-08T18:15:07.150",
  "references": [
    {
      "url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-1305",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@openvpn.net"
    },
    {
      "url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html",
      "tags": [
        "Mailing List",
        "Release Notes"
      ],
      "source": "security@openvpn.net"
    },
    {
      "url": "https://community.openvpn.net/openvpn/wiki/CVE-2024-1305",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.mail-archive.com/openvpn-users@lists.sourceforge.net/msg07534.html",
      "tags": [
        "Mailing List",
        "Release Notes"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@openvpn.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-190"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "tap-windows6 driver version 9.26 and earlier does not properly \ncheck the size data of incomming write operations which an attacker can \nuse to overflow memory buffers, resulting in a bug check and potentially\n arbitrary code execution in kernel space"
    },
    {
      "lang": "es",
      "value": "La versión 9.26 y anteriores del controlador tap-windows6 no verifica correctamente los datos de tamaño de las operaciones de escritura entrantes que un atacante puede usar para desbordar los búfers de memoria, lo que resulta en una verificación de errores y la ejecución de código potencialmente arbitrario en el espacio del kernel."
    }
  ],
  "lastModified": "2026-06-17T07:03:56.383",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openvpn:tap-windows6:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1361B991-0259-40EC-89A2-06B591C84F5C",
              "versionEndIncluding": "9.26.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@openvpn.net"
}