Description
HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
Published: 2026-08-26
Score: 3.9 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow caused by missing hardening protections in the BigFix Quantum Risk Analyzer binary. An attacker may trigger the overflow by feeding crafted input or otherwise manipulating execution flow, potentially leading to non‑privileged code execution within the context of the running process. The flaw is identified as CWE‑121 and presently carries a CVSS score of 3.9, indicating low overall severity but still representing a code‑execution risk.

Affected Systems

Affected product is HCL Software’s BigFix Quantum Risk Analyzer. The specific versions impacted are not enumerated in the available data; it applies to the binary supplied by HCL under current releases that lack industry‑standard hardening. Administrators should verify the version of the installed bundle against HCL documentation for exposed builds.

Risk and Exploitability

Given its CVSS rating of 3.9, the risk is considered low from an exploitability standpoint. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Because the application is a desktop binary, the likely attack vector is local execution, but a malicious actor could potentially exploit it from a compromised network if the binary is callable remotely. No published remote exploitation evidence is known at this time.

Generated by OpenCVE AI on August 27, 2026 at 00:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult HCL support article KB0133289 for guidance on acquiring and deploying the patch for BigFix Quantum Risk Analyzer.
  • Apply the update or patch that supplies stack protection for the application as soon as possible.
  • Restrict user privileges and network access to the binary, ensuring that only trusted users can run or communicate with it.
  • Monitor system and application logs for anomalous activity that could indicate exploitation attempts.

Generated by OpenCVE AI on August 27, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
Title HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-26T22:02:27.455Z

Reserved: 2026-01-05T16:08:06.682Z

Link: CVE-2026-21807

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T23:17:12.713

Modified: 2026-08-26T23:17:12.713

Link: CVE-2026-21807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T00:30:14Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow