First published: Tue Dec 28 2021(Updated: )
ForeScout - SecureConnector Local Service DoS - A low privilaged user which doesn't have permissions to shutdown the secure connector service writes a large amount of characters in the installationPath. This will cause the buffer to overflow and override the stack cookie causing the service to crash.
Credit: cna@cyber.gov.il
Affected Software | Affected Version | How to fix |
---|---|---|
Forescout SecureConnector | =11.0.4.1024 |
HotFix was released
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36724 is classified as a DoS vulnerability with low privileges allowing a buffer overflow.
To fix CVE-2021-36724, update to the latest version of ForeScout SecureConnector that addresses this vulnerability.
CVE-2021-36724 affects users running ForeScout SecureConnector version 11.0.4.1024.
A local user with low privileges can exploit CVE-2021-36724 by writing excessive characters in the installationPath.
Exploiting CVE-2021-36724 can lead to denial of service conditions for the SecureConnector.