CVE-2021-36724: ForeScout - SecureConnector Local Service DoS
ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36724?
CVE-2021-36724 is classified as a DoS vulnerability with low privileges allowing a buffer overflow.
How can I fix CVE-2021-36724?
To fix CVE-2021-36724, update to the latest version of ForeScout SecureConnector that addresses this vulnerability.
Who is affected by CVE-2021-36724?
CVE-2021-36724 affects users running ForeScout SecureConnector version 11.0.4.1024.
What can exploit CVE-2021-36724?
A local user with low privileges can exploit CVE-2021-36724 by writing excessive characters in the installationPath.
What are the consequences of CVE-2021-36724?
Exploiting CVE-2021-36724 can lead to denial of service conditions for the SecureConnector.