Main
Vulnerability Database
Exploits
ID:5545 - Exploit for Input validation error in Microsoft products - CVE-2021-1647
ID:5545 - Exploit for Input validation error in Microsoft products - CVE-2021-1647
Published: June 9, 2021
Vulnerability identifier: #VU49401
Vulnerability risk: Critical
CVE-ID: CVE-2021-1647
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Microsoft Security Essentials
Windows Defender
Microsoft System Center Endpoint Protection
Microsoft Security Essentials
Windows Defender
Microsoft System Center Endpoint Protection
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install updates from vendor's website.