First published: Thu Dec 23 2021(Updated: )
NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker to takeover a Remote Desktop Session.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp Virtual Desktop Service | <6.1.21356.1837 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27007 has a critical severity level as it allows an unauthenticated attacker to take over a Remote Desktop Session.
To fix CVE-2021-27007, update your NetApp Virtual Desktop Service to a version later than 6.1.21356.1837.
Organizations using NetApp Virtual Desktop Service with an HTML5 gateway prior to version 6.1.21356.1837 are affected by CVE-2021-27007.
CVE-2021-27007 can lead to unauthorized access and potential takeover of remote desktop sessions.
Currently, the best mitigation for CVE-2021-27007 is to apply the recommended software updates from NetApp.