PT-2021-21558 · Microsoft · Windows+1

Published

2021-09-14

·

Updated

2021-09-24

·

CVE-2021-37181

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cerberus DMS versions 4.0 through 5.0 before v5.0 QU1 Desigo CC Compact versions 4.0 through 5.0 before V5.0 QU1 Desigo CC versions 4.0 through 5.0 before V5.0 QU1
Description The application deserialises untrusted data without sufficient validations, which could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected.
Recommendations For Cerberus DMS versions 4.0 through 5.0 before v5.0 QU1, update to version v5.0 QU1 or later. For Desigo CC Compact versions 4.0 through 5.0 before V5.0 QU1, update to version V5.0 QU1 or later. For Desigo CC versions 4.0 through 5.0 before V5.0 QU1, update to version V5.0 QU1 or later. As a temporary workaround, consider restricting access to the CCOM communication component until a patch is available.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37181

Affected Products

Internet Explorer
Windows