VDB
CVE-2021-22717
CVE-2021-22717
PUBLISHED
CVSS 7.800000190734863 HIGH
De multiples vulnérabilités ont été découvertes dans les produits Schneider Electric. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance.
EPSS 11.34% · 93.7th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
11.34%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows Server | 2008 R2 for x64-based Systems Service Pack 1 (Core installation), 2008 R2 for Itanium-Based Systems Service Pack 1, 2008 R2 for x64-based Systems Service Pack 1 |
| Microsoft | Windows | *, *, 7 for x64-based Systems Service Pack 1 |
| Schneider Electric | N/A |
Exploit Intelligence
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0803 (circl)
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0803 (circl)
- http://packetstormsecurity.com/files/153034/Microsoft-Windows-Win32k-Privilege-Escalation.html (circl)
- CIRCL exploited: CVE-2019-0803 (circl-sighting)
- CIRCL seen: CVE-2019-0803 (circl-sighting)
- CIRCL seen: CVE-2019-0803 (circl-sighting)
- CIRCL seen: CVE-2019-0803 (circl-sighting)
- CIRCL seen: CVE-2019-0803 (circl-sighting)
- CIRCL seen: CVE-2019-0803 (circl-sighting)
- CIRCL seen: CVE-2019-0803 (circl-sighting)
…and 54 more exploits
Timeline
- May 23, 2014 PoC Published
- Apr 10, 2019 PoC Published
- Jul 18, 2019 PoC Published
- Jan 21, 2020 PoC Published
- Jun 26, 2020 PoC Published
- Aug 17, 2020 PoC Published
- Sep 17, 2020 PoC Published
- Oct 3, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Oct 20, 2020 PoC Published
- Oct 20, 2020 PoC Published
- Oct 21, 2020 PoC Published
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-103-01 advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-103-02 advisory
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0803 url
- http://packetstormsecurity.com/files/153034/Microsoft-Windows-Win32k-Privilege-Escalation.html url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0803 url