CVE-2025-15317 Details
Description
Tanium addressed an uncontrolled resource consumption vulnerability in Tanium Server.
An uncontrolled resource consumption vulnerability has been identified in Tanium Server, specifically in versions 7.4.6 prior to 7.4.6.1154, 7.5.6 prior to 7.5.6.1164, and several versions in the 2024H1 and 2024H2 releases. This vulnerability allows an authenticated Tanium user with the 'Interact - Ask Dynamic Questions' permission to execute a denial-of-service attack against the Tanium Server.
Users can upgrade to Tanium Server version 7.4.6.1154, 7.5.6.1164, 7.6.2.1303 (Update 14), or 7.6.4.2124 (Update 3) to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2025-013 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium server | >= 7.4.6, < 7.4.6.1154 >= 7.5.6, < 7.5.6.1164 >= 7.6.2, < 7.6.2.1303 >= 7.6.4, < 7.6.4.2124 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Feb 9, 2026 | New CVE Received | Tanium |