SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2021-27852

Checkbox Survey Deserialization of Untrusted Data Vulnerability

KEVCRITICAL 9.8EPSS 31.9%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
31.95% probability · 98th percentile
CISA KEV
Listed 11 April 2022 · due 2 May 2022
Weakness
CWE-502
Affected
checkbox/survey
Source
cret@cert.org

CISA notes

Versions 6 and earlier for this product are end-of-life and must be removed from agency networks. Versions 7 and later are not considered vulnerable. https://nvd.nist.gov/vuln/detail/CVE-2021-27852

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.