TunnelVision (CVE-2024-3661): How Attackers Can Decloak Routing-Based VPNs For a Total VPN Leak

May 9, 2024
Leviathan Security
Contributed by: Drex DeFord
This article details a novel network technique discovered by researchers that allows an attacker to bypass VPN encapsulation via DHCP (Dynamic Host Configuration Protocol), effectively forcing a target user’s traffic outside of their VPN tunnel. Termed as "decloaking," this method subtly exploits the DHCP without disrupting the VPN's control channel, leaving the user unaware as their data transmissions are not encrypted by the VPN. Despite attempts to inform affected parties, the technique—which is believed to be exploitable since 2002—remains a significant threat. The article emphasizes the difficulty in mitigating this vulnerability due to the essential role DHCP plays in network connectivity and suggests the implementation of network namespaces as a potential fix for systems that support it, like Linux. The research aims to raise awareness within the security community about this threat and the challenge in notifying every VPN provider and user, hoping for wider implementation of effective countermeasures.
