Wireshark Profile Import Path Traversal Vulnerability Allowing Denial-of-Service and Possible Code Execution

Vulnerability

A path traversal vulnerability has been identified in Wireshark versions 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14. This vulnerability arises in the Configuration Profile import feature, where the application fails to properly validate file paths in ZIP archives in the extraction process. As a result, a crafted ZIP file can overwrite files in arbitrary locations, potentially leading to code execution. On POSIX systems, this could involve placing a malicious Lua plugin in a directory that Wireshark loads at startup, executing the code when Wireshark is launched.

Impact

Exploitation of this vulnerability can cause Wireshark to crash or execute arbitrary code, depending on the actions taken by the imported profile.

Reproduction

The vulnerability can be reproduced by creating a ZIP file that exploits the path traversal issue, and then importing this file through the Wireshark Configuration Profiles menu. After importing, Wireshark should be restarted to verify if the payload was executed.

Remediation

Users should upgrade to Wireshark versions 4.6.5, 4.4.15 or later.

Added: May 1, 2026, 12:20 AM
Updated: May 1, 2026, 12:20 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
6.0
remediation
7.7
relevance
7.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.