CVE-2022-41924Active Exploitation(microsoft / tailscale)

MEDIUMCVSS 9.6 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft tailscale systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bound to a local TCP socket, and communicated with the Windows client GUI in cleartext with no Host header verification. This allowed an attacker-controlled website visited by the node to rebind DNS to an attacker-controlled DNS server, and then make local API requests in the client, including changing the coordination server to an attacker-controlled coordination server. An attacker-controlled coordination server can send malicious URL responses to the client, including pushing executables or installing an SMB share. These allow the attacker to remotely execute code on the node. All Windows clients prior to version v.1.32.3 are affected. If you are running Tailscale on Windows, upgrade to v1.32.3 or later to remediate the issue.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-352

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tailscale
  • windows

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
tailscalewindows

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-21: 1Active Exploitation · 2026-03-21: 103-21
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • SH TC@shtc_social
    Active Exploitation

    @skyhancloud @caginus27175 @saffetceliktr "Tailscale veya diğer tunneller" bypass edilemez" demek biraz fazla özgüven kokuyor 🙂 Kriptoyu kırmana gerek yok zaten. Real life'de sistemler algoritmadan değil, implementasyondan kırılır. https://cybersecuritynews.com/hackers-actively-exploiting-cloudflare-tunnels/ https://nvd.nist.gov/vuln/detail/CVE-2022-41925 https://nvd.nist.gov/vuln/detail/CVE-2022-41924

    Post summary

    The tweet references two CVEs tied to Cloudflare tunnels and links to an article confirming hackers are actively exploiting them, but lacks PoC, exploit code, or patch information.

    1001060
    109 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows---
Apptailscaletailscale---

Explore more