CVE-2021-43933
- EPSS 0.22%
- Veröffentlicht 20.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:01
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receiving server, which could cause a denial-of-service condition due to lack of heap memory resources.
- EPSS 0.07%
- Veröffentlicht 20.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:09
The setup program for the affected product configures its files and folders with full access, which may allow unauthorized users permission to replace original binaries and achieve privilege escalation.
CVE-2021-43988
- EPSS 0.44%
- Veröffentlicht 20.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:09
The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of files to gain unauthorized access rights.
CVE-2021-43990
- EPSS 0.2%
- Veröffentlicht 20.04.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:30:09
The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call.
CVE-2021-38483
- EPSS 0.04%
- Veröffentlicht 20.04.2022 16:15:07
- Zuletzt bearbeitet 21.11.2024 06:17:12
The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileges access to overwrite the binary and modify files to gain privilege escalation.