PT-2021-21186 · Unknown · Mik.Starlight

Nicola Staller

·

Published

2021-08-31

·

Updated

2021-09-08

·

CVE-2021-36231

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MIK.starlight version 7.9.5.24363
Description The issue allows authenticated remote attackers to execute operating system commands by crafting serialized objects due to deserialization of untrusted data in multiple functions.
Recommendations For MIK.starlight version 7.9.5.24363, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36231

Affected Products

Mik.Starlight