Unauthenticated Remote Code Execution in Oracle Secure Global Desktop
CVE-2021-2248
10CRITICAL
Summary
A vulnerability exists in the Oracle Secure Global Desktop, part of the Oracle Virtualization suite, allowing an unauthenticated attacker to exploit the system over the network. This vulnerability is particularly concerning as it enables unauthorized access that could lead to complete takeover of the affected desktop, potentially impacting additional products involved in the virtualization environment. Attackers leveraging this flaw can target multiple protocols, making it easier to bypass traditional defenses. Organizations using Oracle Secure Global Desktop should implement immediate security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Secure Global Desktop 5.6
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved