CVE-2021-40425
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. An IOCTL_B03 request with specific invalid data causes a similar issue in the device driver WRCore_x64. An attacker can issue an ioctl to trigger this vulnerability.
Se presenta una vulnerabilidad de lectura fuera de límites en IOCTL GetProcessCommand y B_03 de Webroot Secure Anywhere versión 21.4. Un ejecutable especialmente diseñado puede conllevar a una denegación de servicio. Un atacante puede emitir un ioctl para desencadenar esta vulnerabilidad. Se presenta una vulnerabilidad de lectura fuera de límites en la IOCTL GetProcessCommand y B_03 de Webroot Secure Anywhere 21.4. Una petición IOCTL_B03 con datos específicos no válidos causa un problema similar en el controlador de dispositivo WRCore_x64. Un atacante puede emitir un ioctl para desencadenar esta vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-01 CVE Reserved
- 2022-04-14 CVE Published
- 2023-11-05 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1433 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Webroot Search vendor "Webroot" | Secureanywhere Search vendor "Webroot" for product "Secureanywhere" | 21.4 Search vendor "Webroot" for product "Secureanywhere" and version "21.4" | - |
Affected
|