New attack leaks VPN traffic using rogue DHCP servers
ID: 6fc530b0-7742-5b6d-bd18-c1885d5b838e
STIX ID: report--6fc530b0-7742-5b6d-bd18-c1885d5b838e
Feed Name: Bleeping Computer
Leviathan Security disclosed "TunnelVision" (CVE-2024-3661), a DHCP option 121 routing abuse that lets a rogue DHCP server rewrite client routing so VPN traffic is sent to a local/malicious gateway instead of through the encrypted tunnel; a proof-of-concept and vendor notifications were published, multiple OSes are affected (Windows, Linux, macOS, iOS), Android is not impacted, and mitigations include ignoring DHCP option 121, using network namespaces, hardening VPN clients, and avoiding untrusted networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
