Sceawere
Vulnerability Detail
CVE-2026-95394UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft Network Monitor Infinite Loop
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 15h ago
- Vendor
- Wireshark Foundation
- Product
- Wireshark
- Attack Type
- CWE-606: Unchecked Input for Loop Condition
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Microsoft Network Monitor file parser large loop in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-09-29T10:17:15.757Z",
"pubdate": "2026-09-29T10:17:15.757Z",
"executiveSummary": "This vulnerability involves an infinite loop condition within the Microsoft Network Monitor file parser, classified as a Denial of Service (DoS) flaw.\nThe issue affects specific versions within the 4.6.x and 4.4.x release branches.\nExploitation allows an attacker to trigger resource exhaustion by submitting a maliciously crafted capture file for parsing, leading to application hang or crash.\nThe vulnerability poses significant availability risks for systems analyzing network traffic, as the process cannot recover without manual intervention.\nNo specific authentication or elevated privileges are required to initiate the attack; however, the attacker must be able to influence the input file processed by the monitor.\nThe risk is primarily localized to the parsing engine, which effectively stops monitoring operations upon successful triggering of the loop.",
"technicalDetails": "The vulnerability originates in the file parsing logic of Microsoft Network Monitor, specifically within the module responsible for interpreting capture file formats.\nThe root cause is an improper boundary check or state transition logic that fails to terminate a parsing loop when encountering malformed data structures.\nWhen the parser processes a crafted file containing specific metadata or header field arrangements that trigger the flaw, the logic enters an infinite loop, consuming 100% of the CPU core assigned to the process.\nThis behavior results in a DoS state, as the application becomes unresponsive and ceases all network monitoring or packet analysis tasks.\nAffected product versions include 4.6.0 through 4.6.8 and 4.4.0 through 4.4.18.\nThe attack flow follows a predictable sequence: First, the attacker creates a malicious packet capture file (.cap) that mimics valid file structures but incorporates specific byte sequences that induce the loop condition in the parser.\nSecond, the attacker provides this file to the victim system, either through direct delivery, social engineering, or by causing an automated monitoring system to ingest the file from an external repository or network location.\nThird, once Microsoft Network Monitor attempts to load or analyze the file, the underlying parser enters the infinite loop, immediately resulting in resource exhaustion.\nBecause the vulnerability is triggered during the ingestion phase of the file parser, there are no complex heap-spraying or memory corruption requirements; the threat is purely an algorithmic complexity/logic error.\nNetwork exposure depends on the configuration of the monitor; however, any environment where Microsoft Network Monitor is configured to automatically parse or analyze captured data is at risk.\nPost-exploitation impact is limited to the availability domain, specifically the loss of visibility into network traffic that the monitor is intended to provide, potentially masking other malicious activities occurring on the network during the period of service interruption."
}