Impact
The vulnerability resides in the AdapterState function of the IOCTL handler in Mullvad's wireguard.sys 0.10.1. Improper update of reference count can cause the driver to mismanage resources, potentially leading to a memory corruption or crash that results in denial of service for the local user. This flaw requires local access to the machine, so an attacker needs to be able to execute code on the target system.
Affected Systems
The affected product is Mullvad's wireguard.sys version 0.10.1. No other versions or vendors are listed in the current data, so targeting is limited to installations running this specific release.
Risk and Exploitability
The CVSS score of 4.6 indicates a medium severity flaw. Because the EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, the publicly available exploit still represents a moderate risk scenario; an attacker with local privileges could exploit the flaw to crash the driver and stop the VPN service, which may disrupt user connectivity.
OpenCVE Enrichment