PT-2021-5674 · Microsoft · Defender For Iot
Published
2021-12-14
·
Updated
2023-12-28
·
CVE-2021-41365
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Defender for IoT (affected versions not specified)
Description
The issue is related to incorrect code generation management in Microsoft Defender for IoT, allowing a remote attacker to execute arbitrary code using a specially crafted request. This can lead to privilege escalation. The vulnerability may be exploited through the
maintenanceWindow endpoint, potentially allowing SQL injection.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Code Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Defender For Iot