Tanium Server Uncontrolled Resource Consumption Vulnerability Leading to Denial-of-Service
Vulnerability
An uncontrolled resource consumption vulnerability has been identified in Tanium Server, specifically in versions 7.4.6 prior to 7.4.6.1154, 7.5.6 prior to 7.5.6.1164, and several versions in the 2024H1 and 2024H2 releases. This vulnerability allows an authenticated Tanium user with the 'Interact - Ask Dynamic Questions' permission to execute a denial-of-service attack against the Tanium Server.
Impact
Exploitation of this vulnerability could result in a denial-of-service condition on the Tanium Server, causing it to become unresponsive or unavailable.
Remediation
Users can upgrade to Tanium Server version 7.4.6.1154, 7.5.6.1164, 7.6.2.1303 (Update 14), or 7.6.4.2124 (Update 3) to address this vulnerability.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
