WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permissions thus perform hijack attacks to execute arbitrary code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2021-09-15T19:10:22.691086Z

Updated: 2024-09-17T00:42:01.361Z

Reserved: 2021-08-02T00:00:00

Link: CVE-2021-37909

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-09-15T19:15:09.873

Modified: 2021-09-28T14:33:21.167

Link: CVE-2021-37909

cve-icon Redhat

No data.