PT-2024-6161 · Unknown · Tap-Windows6

Vladimir Tokarev

·

Published

2024-03-19

·

Updated

2025-08-22

·

CVE-2024-1305

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions tap-windows6 driver version 9.26 and earlier
Description The issue is related to the tap-windows6 driver not properly checking the size data of incoming write operations, which can be used by an attacker to overflow memory buffers. This can result in a bug check and potentially allow for arbitrary code execution in kernel space. The vulnerability is associated with an integer overflow.
Recommendations For tap-windows6 driver version 9.26 and earlier, update to a version later than 9.26 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-07081
CVE-2024-1305

Affected Products

Tap-Windows6