CVE-2021-22908

Description

A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
31.772

Associated Vulnerability

VulnerabilityOS Platform
Remote code execution in Pulse Connect Secure (CVE-2021-22908)Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r1Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r2Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r2.1Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r3Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r3.1Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r3.2Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r3.3Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.1Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.1.r1Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r3.5Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r4Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r4.1Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r5.0Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.0.r6.0Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.1.r10.0Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.1.r10.2Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.1.r11.0Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.1.r11.1Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.1.r11.3Windows
Vulnerabilities CVE-2021-22894,CVE-2021-22899,CVE-2021-22900,CVE-2021-22908 are affected in Ivanti Connect Secure 9.0.r1.0Windows
Vulnerabilities CVE-2021-22894,CVE-2021-22899,CVE-2021-22900,CVE-2021-22908 are affected in Ivanti Connect Secure 9.0.r2.0Windows
Vulnerabilities CVE-2021-22894,CVE-2021-22899,CVE-2021-22900,CVE-2021-22908 are affected in Ivanti Connect Secure 9.0.r3.0Windows
Vulnerabilities CVE-2021-22894,CVE-2021-22899,CVE-2021-22900,CVE-2021-22908 are affected in Ivanti Connect Secure 9.0.r4.0Windows
Multiple Vulnerabilities are affected in Ivanti Connect Secure 9.1.r11.4Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-336891Ivanti Secure Access Client (22.7.28369) (Formerly Pulse Secure) (Manual Upload Required)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234