CVE-2022-41924

CRITICAL

Tailscale < 1.32.3 - Remote Code Execution via Local API Host Header Spoofing

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-41924. PoCs published by oalieno.

AI-analyzed exploit summary This repository contains a README linking to a blog post about CVE-2022-41924, a vulnerability in Tailscale. No actual exploit code or technical details are provided in the repository itself.

Description

A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bound to a local TCP socket, and communicated with the Windows client GUI in cleartext with no Host header verification. This allowed an attacker-controlled website visited by the node to rebind DNS to an attacker-controlled DNS server, and then make local API requests in the client, including changing the coordination server to an attacker-controlled coordination server. An attacker-controlled coordination server can send malicious URL responses to the client, including pushing executables or installing an SMB share. These allow the attacker to remotely execute code on the node. All Windows clients prior to version v.1.32.3 are affected. If you are running Tailscale on Windows, upgrade to v1.32.3 or later to remediate the issue.

Exploits (1)

nomisec WRITEUP
by oalieno · poc
https://github.com/oalieno/CVE-2022-41924

This repository contains a README linking to a blog post about CVE-2022-41924, a vulnerability in Tailscale. No actual exploit code or technical details are provided in the repository itself.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Theoretical
Reliability
Theoretical
Target: Tailscale (version not specified)
No auth needed
Prerequisites: Access to the blog post for details
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Technical Description, Third Party Advisory
https://emily.id.au/tailscale

Scores

CVSS v3 9.6
EPSS 0.0155
EPSS Percentile 72.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-346 CWE-352
Status published
Products (2)
Go/tailscale.com 0 - 1.32.3Go
tailscale/tailscale < 1.32.3
Published Nov 23, 2022
Tracked Since Feb 18, 2026