Tanium Cloud Workloads Enforce Client Extension Use-After-Free Vulnerability
Vulnerability
A use-after-free vulnerability has been identified in the Tanium Cloud Workloads Enforce client extension. This vulnerability could allow an attacker with access to a Tanium Client Container to conduct a denial-of-service attack against the Enforce client extension.
Impact
Exploitation of this vulnerability could lead to a denial-of-service condition on the Enforce client extension.
Remediation
Users can upgrade to Tanium Cloud Workloads version 1.0.222 or later. For on-premises customers, it is also necessary to redeploy the Tanium Cluster Client Container. Tanium Cloud customers should follow the same procedure.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
