CVE-2025-15320 Details
Description
Tanium addressed a denial of service vulnerability in Tanium Client.
A denial-of-service vulnerability has been identified in Tanium Client versions 7.4 prior to 7.4.10.1117, as well as in several 2024 and 2025 releases. This vulnerability allows an attacker with access to a system running the Tanium Client to disrupt the Tanium Client API, potentially causing service interruptions.
Users can upgrade to Tanium Client version 7.4.10.1117 or later. For the 2024H1 release, update to version 7.6.2.1327 or later. For the 2024H2 release, update to version 7.6.4.2160 or later. For the 2025H1 release, update to version 7.7.3.8231 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tanium.com/TAN-2025-023 | Tanium | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-605 | Multiple Binds to the Same Port | Tanium |
Affected Products
| Product | Versions |
|---|---|
| tanium tanium | >= 7.4.10.0, < 7.4.10.1118 >= 7.6.2.0, < 7.6.2.1327 >= 7.6.4.0, < 7.6.4.2160 >= 7.7.3.0, < 7.7.3.8231 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Tanium |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Feb 6, 2026 | New CVE Received | Tanium |