ZeroHour

CVE-2021-27852

KEV

Unauthenticated Deserialization RCE in Checkbox Survey 6 and Earlier

CISA: Checkbox Survey Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.8 critical
EPSS
32%p98
Published
()
KEV added
AI analysis

CVE-2021-27852 is a deserialization of untrusted data flaw (CWE-502) in CheckboxWeb.dll of Checkbox Survey, allowing an unauthenticated remote attacker to execute arbitrary code. An attacker triggers it by sending maliciously crafted serialized data to the vulnerable application over the network, without needing credentials. Successful exploitation yields arbitrary code execution on the server hosting the survey application. Only Checkbox Survey versions 6 and earlier are affected; versions 7 and later are not considered vulnerable, but version 6 and earlier is end-of-life. The flaw is listed in the CISA Known Exploited Vulnerabilities catalog (added 2022-04-11), indicating known exploitation, and EPSS estimates a 31.9% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

What to do: Per CISA's required action, remove Checkbox Survey versions 6 and earlier from agency networks, as they are end-of-life, or upgrade to version 7 or later, which is not considered vulnerable. Check for internet-facing servers exposing CheckboxWeb.dll/Checkbox Survey endpoints and treat any version 6 or earlier installation as potentially compromised. Monitor CISA guidance, since ransomware association is currently unknown and CVSS scoring is pending.

Affected
Checkbox SurveyVersions 6 and earlier (versions 7 and later are not considered vulnerable)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

CISA Known Exploited Vulnerability
Affected
Checkbox Checkbox Survey
Required action
Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable.
Due date
Ransomware use
Unknown
Vendors
checkbox
Products
survey
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news