CVE-2021-46873: Race Condition
WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one static private key becomes permanently useless.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-46873?
The severity of CVE-2021-46873 is considered high due to the potential for a static private key to become permanently unusable.
How do I fix CVE-2021-46873?
To fix CVE-2021-46873, users should update to the latest version of WireGuard that addresses this time setting issue.
What versions of WireGuard are affected by CVE-2021-46873?
CVE-2021-46873 specifically affects WireGuard version 0.5.3 on Windows.
Can CVE-2021-46873 be exploited through unauthenticated NTP?
Yes, CVE-2021-46873 can be exploited if an attacker can manipulate the system time via unauthenticated NTP.
What happens if my system's time is set to a future value in relation to CVE-2021-46873?
If your system time is set to a future value, it could render your static private key in WireGuard permanently useless.