Impact
The vulnerability arises from the processing of arbitrarily compressed data by Tanium Findings. This allows an attacker to craft a compressed payload that expands to an enormous size, exhausting memory or CPU and potentially causing the application to crash or become unresponsive. The weakness aligns with CWE-409, highlighting improper handling of integer overflow or wraparound during decompression.
Affected Systems
The affected system is Tanium Findings, a software component used for endpoint data collection and analysis. No specific versions are listed, so all deployments of Findings could be vulnerable until a mitigation is applied.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity risk. EPSS data is not available; the vulnerability is not listed in CISA KEV, suggesting no known active exploitation yet. The likely attack vector is remote, though data input channels are not explicitly defined. Without dedicated patches, the best practice is to constrain input size and monitor system resources.
OpenCVE Enrichment