CVE-2026-102758: Microsoft NetX Secure vulnerability

Published Sep 29, 2026
·
Updated

The nxsecurex509asn1tlvblockparse() function parses ASN.1 TLV (tag-length-value) blocks out of DER-encoded data. It is the primitive underneath all X.509 certificate parsing in NetX Secure, and therefore runs on certificates supplied by a remote peer during the TLS handshake.

The function reads the one-byte ASN.1 tag from the caller's buffer before checking that the buffer holds at least one byte. When a caller passes a remaining length of zero, the guard correctly returns NXSECUREX509ASN1LENGTHTOOLONG, but the read has already happened one byte past the end of the buffer.

code:

nxsecure/src/nxsecurex509asn1tlvblockparse.c

UINT nxsecurex509asn1tlvblockparse(const UCHAR buffer, ULONG bufferlength, USHORT tlvtype,

USHORT tlvtagclass, ULONG tlvlength, const UCHAR tlvdata, ULONG headerlength)

{

UINT currentindex;

USHORT currenttag;

ULONG length;

ULONG lengthbytes;

currentindex = 0; currenttag = buffer[currentindex]; / <-- read before the bounds check / if (bufferlength < 1) { return(NXSECUREX509ASN1LENGTHTOOLONG); }

The remainder of the function is correctly ordered. The multi-byte length path is guarded by lengthbytes > 4 || lengthbytes > bufferlength before its read loop, the decoded value is checked against length > bufferlength, and the second single-byte length read follows its own bufferlength < 1 guard. The tag read is the only load placed ahead of its check.

Affected Software

1 affected component
Microsoft NetX Secure

Event History

Sep 29, 2026
CVE Published
via MITRE·05:26 PM
Data Sourced
via MITRE·05:26 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionWeakness

Frequently Asked Questions

1

Which deployments are exposed to this issue?

NetX Secure deployments that parse X.509 certificates from remote peers during TLS handshakes can reach the affected parsing primitive. The issue is in the ASN.1 TLV parser used underneath X.509 certificate parsing.

2

What does an attacker need to trigger the out-of-bounds read?

An attacker needs to supply certificate data that causes the parser to be called with a remaining buffer length of zero. The function reads the ASN.1 tag byte before checking whether at least one byte remains.

3

How can I determine whether my source tree contains the vulnerable code?

Inspect _nx_secure_x509_asn1_tlv_block_parse() in nx_secure_x509_asn1_tlv_block_parse.c. It is affected if it assigns current_tag from buffer[current_index] before checking whether *buffer_length is less than 1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203