CVE-2021-27852
Checkbox Survey Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 31.95% probability · 98th percentile
- CISA KEV
- Listed 11 April 2022 · due 2 May 2022
- Weakness
- CWE-502
- Affected
- checkbox/survey
- Source
- cret@cert.org
CISA notes
Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable. https://nvd.nist.gov/vuln/detail/CVE-2021-27852
References
- https://www.kb.cert.org/vuls/id/706695Third Party Advisory, US Government Resource
- https://www.kb.cert.org/vuls/id/706695Third Party Advisory, US Government Resource
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27852US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.