WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permissions thus perform hijack attacks to execute arbitrary code.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24387 | WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permissions thus perform hijack attacks to execute arbitrary code. |
Fixes
Solution
Update to version 1.0.21.0520
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5093-76f04-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-17T00:42:01.361Z
Reserved: 2021-08-02T00:00:00
Link: CVE-2021-37909
No data.
Status : Modified
Published: 2021-09-15T19:15:09.873
Modified: 2024-11-21T06:16:01.957
Link: CVE-2021-37909
No data.
OpenCVE Enrichment
No data.
EUVD