Impact
A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. After the TLS handshake, a remote endpoint can send an oversized decrypted record that causes the driver to write beyond the bounds of a heap allocation. The flaw can lead to memory corruption, disclosure of adjacent heap contents, or crash of the client process. The impact is confined to the client process, but the lack of authentication or user interaction and the ability to trigger the bug remotely makes it a potential vector for remote code execution.
Affected Systems
The vulnerability affects MongoDB Inc.’s MongoDB C Driver when compiled for Windows with the Windows TLS backend. All Windows builds of the driver prior to the availability of a patch are vulnerable; specific version numbers are not listed in the advisory.
Risk and Exploitability
The CVSS score of 9.2 indicates high severity. The EPSS score of less than 1% shows a low but nonzero probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Because the flaw can be triggered by any network participant without prior authentication, an exposed client could be compromised by an attacker able to observe or influence encrypted traffic. No authentication or user interaction is required to trigger the issue; the attack vector is purely remote network traffic entering the driver’s TLS processing.
OpenCVE Enrichment