First published: Tue Jul 13 2021(Updated: )
Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 does not accomplish the intended defense against local administrators who can replace the Visual C++ runtime DLLs (in %WINDIR%\system32) with malicious ones.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Stormshield Endpoint Security | >=2.0.0<=2.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35957 is a vulnerability in Stormshield Endpoint Security Evolution 2.0.0 through 2.0.2 that allows local administrators to replace the Visual C++ runtime DLLs with malicious ones.
CVE-2021-35957 has a severity rating of medium, with a CVSS score of 6.7.
CVE-2021-35957 allows local administrators to replace the Visual C++ runtime DLLs, potentially compromising the security defenses provided by Stormshield Endpoint Security Evolution.
Stormshield Endpoint Security Evolution versions 2.0.0 through 2.0.2 are affected by CVE-2021-35957.
To mitigate CVE-2021-35957, it is recommended to update Stormshield Endpoint Security Evolution to a version that addresses the vulnerability and monitor for any suspicious activity related to the Visual C++ runtime DLLs.