Impact
Tanium Threat Response includes a compression bomb vulnerability that allows an attacker to craft a compressed payload which, when decompressed by the application, consumes excessive memory or CPU. The impact is resource exhaustion, leading to degraded performance or a denial of service. The weakness is classified under CWE‑409. No evidence of data disclosure or integrity compromise is provided in the current information.
Affected Systems
The affected product is Tanium Threat Response. Specific version information is not provided, so all currently installing releases should be reviewed for updates or confirmed safe by the vendor.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or via a domain where the Threat Response component processes user‑supplied compressed files. Based on the description, it is inferred that exploitation would require the ability to deliver a specially crafted compressed payload to the affected system.
OpenCVE Enrichment