ZeroHour

CVE-2021-37909

CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description

WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permissions thus perform hijack attacks to execute arbitrary code.

Vendors
tssservisignadapter project
Products
tssservisignadapter
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.