ID:5545 - Exploit for Input validation error in Microsoft products - CVE-2021-1647

 
Main Vulnerability Database Exploits ID:5545 - Exploit for Input validation error in Microsoft products - CVE-2021-1647

ID:5545 - Exploit for Input validation error in Microsoft products - CVE-2021-1647

Published: June 9, 2021


Vulnerability identifier: #VU49401
Vulnerability risk: Critical
CVE-ID: CVE-2021-1647
CWE-ID: CWE-20
Exploitation vector: Remote access
Vulnerable software:
Microsoft Security Essentials
Windows Defender
Microsoft System Center Endpoint Protection

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.