CVE-2021-39392: Critical severity myLittleTools Mylittlebackup vulnerability
The management tool in MyLittleBackup up to and including 1.7 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MyLittleBackup management toolto a version that resolves this vulnerability.Fixed in 1.7
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39392?
CVE-2021-39392 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2021-39392?
To fix CVE-2021-39392, update MyLittleBackup to version 1.8 or later, which addresses this vulnerability.
What kind of vulnerability is CVE-2021-39392?
CVE-2021-39392 is a remote code execution vulnerability caused by a hardcoded machineKey in the web.config file.
Who is affected by CVE-2021-39392?
All installations of MyLittleBackup up to and including version 1.7 are affected by CVE-2021-39392.
What are the potential impacts of CVE-2021-39392?
The potential impacts of CVE-2021-39392 include unauthorized execution of arbitrary code on affected systems.