PT-2022-26154 · Tailscale · Tailscale

Emily Trau

+1

·

Published

2022-11-21

·

Updated

2025-08-07

·

CVE-2022-41924

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:H
Name of the Vulnerable Software and Affected Versions Tailscale Windows client versions prior to v1.32.3
Description A vulnerability in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon tailscaled, enabling remote code execution. The local API was bound to a local TCP socket and communicated with the Windows client GUI in cleartext with no Host header verification, allowing an attacker-controlled website to rebind DNS to an attacker-controlled DNS server and make local API requests. This can lead to an attacker-controlled coordination server sending malicious URL responses, including pushing executables or installing an SMB share, which allows remote code execution on the node.
Recommendations If you are running Tailscale on Windows, upgrade to v1.32.3 or later to remediate the issue.

Exploit

Fix

Origin Validation Error

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-41924
GHSA-VQP6-RC3H-83CP
GO-2022-1120

Affected Products

Tailscale