CVE-2021-37909
—CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
Modified
Description
WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permissions thus perform hijack attacks to execute arbitrary code.
- Vendors
- tssservisignadapter project
- Products
- tssservisignadapter
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.