ZDI-26-747: Wireshark RF4CE Packet Parsing Buffer Overflow Remote Code Execution Vulnerability
ZDI disclosed a Wireshark RF4CE parsing buffer overflow enabling remote code execution, CVE-2026-96417.
ZDI-26-747 describes a buffer overflow in Wireshark's RF4CE packet parser that could let a remote attacker run arbitrary code. Exploitation requires the target to open a malicious capture or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-96417. No in-the-wild exploitation is mentioned.
- RF4CE packet parsing has a buffer overflow.
- Successful exploitation can execute arbitrary code.
- User must open a malicious file or page.
- ZDI rates it CVSS 7.8 as CVE-2026-96417.
Vulnerabilities mentionedAll →
- published —
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-96417 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Wireshark. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-96417.
This source does not provide full text. Read it at zerodayinitiative.com.