An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is not a valid vulnerability. Their DNS Security for Endpoint solution includes an optional feature to provide extra information on the originating process that made a DNS request. The lack of process identification in DNS logs is therefore falsely categorized as a DoS issue.
According to the report, the vulnerability affects the Threat To Process Correlation module that is part of the DNS Security for Endpoint functionality. An attacker could allegedly trigger a DoS condition through interaction with this module. Heimdal argues, however, that the described behavior is merely a lack of process identification in DNS logs — an optional informational feature — not an actual security flaw. The manufacturer strongly denies that the lack of logging the source process of DNS requests constitutes a DoS class vulnerability.
According to the report description, an attacker could cause a denial of service (DoS) on the protected system. However, the manufacturer disputes this classification, indicating that the actual impact on system availability is minimal or nonexistent.
Patches available from the manufacturer should be applied according to references. Due to the dispute over the validity of the vulnerability, it is recommended to contact Heimdal Security to obtain an official statement and potentially update the agent to the latest available version.
Heimdal Thor agent in versions 3.4.2 and earlier on Microsoft Windows systems and versions 2.6.9 and earlier on Apple macOS systems.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HApple macOS
OSAppleall versionsHeimdalsecurity Thor
APPHeimdalsecurity≤ 3.5.3≤ 2.6.9Microsoft Windows
OSMicrosoftall versions
Related vulnerabilities
Pominięcie uwierzytelniania w Screen Sharing na macOS
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP