Arbitrary Command Execution in Microsoft Windows Products
CVE-2021-21876
9.1CRITICAL
What is CVE-2021-21876?
This vulnerability allows attackers to execute arbitrary commands on affected Microsoft Windows products by sending specially-crafted HTTP PUT requests. If exploited, an attacker could gain unauthorized access to execute commands, potentially compromising the system's integrity. This requires authentication, meaning an attacker must possess valid credentials to trigger the vulnerability. Affected users should apply security patches to mitigate the associated risks. For more detailed information, visit Talos Intelligence.
Affected Version(s)
Lantronix Lantronix PremierWave 2050 8.9.0.0R4 (in QEMU)