Live data from Hacker News

CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows

emily.id.au

1–10 of 147 posts

Re: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows

#3
The client app is not indicating that 1.32.3 for Windows is available yet but the download link on the site has been updated.

Tailscale client downloads are extremely slow at the moment, so I suggest you distribute one copy manually around your tailnet rather than bogging down their servers even more.

Re: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows

#4
post #3

The client app is not indicating that 1.32.3 for Windows is available yet but the download link on the site has been updated. Tailscale client downloads are extremely slow at the moment, so I suggest you distribute one copy manually around your tailnet rather than bogging down their servers even more.

Tailscalar here.

The Windows client caches the current version for a while, so may not yet have v1.32.3 available on your device. In that case, you can still pull the latest release from http://pkgs.tailscale.com/stable.

Re: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows

#5
Do they have enough logs to reach out to people that were affected? As far as vulnerabilities go, this set is one is one of the worst ones I've seen this decade, and they seem rather straightforward.

Would be nice to get a blog post from them that goes a bit into impact, not just a report that tells you to update. It's nice that they responded quickly, but I feel like this shouldn't have happened in the first place for a network security company and it makes the Windows client feel like a bit of an afterthought. Looks like they have a PR open to switch it to named pipes, I hope that is properly reviewed by someone that knows Windows APIs before it's merged.

Re: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows

#6
post #4
post #3

The client app is not indicating that 1.32.3 for Windows is available yet but the download link on the site has been updated. Tailscale client downloads are extremely slow at the moment, so I suggest you distribute one copy manually around your tailnet rather than bogging down their servers even more.

Tailscalar here. The Windows client caches the current version for a while, so may not yet have v1.32.3 available on your device. In that case, you can still pull the latest release from http://pkgs.tailscale.com/stable .

Tailscale admin here, politely requesting client update push capability. Being able to see endpoint version is helpful, I will be suspending unpatched endpoints in the near future.

Re: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows

#7
> The speed and quality of Tailscale's response to our report is unlike any vendor interaction I have experienced, and suggests a deep commitment to keeping their customers safe.

I have mixed feelings here as a Tailscale customer.

Yes a quick response is great, but this actual security issue is pretty terrible IMHO.

Anything other than an immediate response would have been akin to lighting their company on fire and walking away.

Re: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows

#8
post #5

Do they have enough logs to reach out to people that were affected? As far as vulnerabilities go, this set is one is one of the worst ones I've seen this decade, and they seem rather straightforward. Would be nice to get a blog post from them that goes a bit into impact, not just a report that tells you to update. It's nice that they responded quickly, but I feel like this shouldn't have happened in the first place f…

edit: I stand corrected as pointed out by the replies below. Curious what logs they had to prove this!

Original comment:

> Do they have enough logs to reach out to people that were affected?

It happens on the client, there are no server logs that Tailscale could check

Re: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows

#9
post #5

Do they have enough logs to reach out to people that were affected? As far as vulnerabilities go, this set is one is one of the worst ones I've seen this decade, and they seem rather straightforward. Would be nice to get a blog post from them that goes a bit into impact, not just a report that tells you to update. It's nice that they responded quickly, but I feel like this shouldn't have happened in the first place f…

"Reviewing all logs confirms this vulnerability was not triggered or exploited."
Post reply on HN