CVE-2021-40837: Denial-of-Service (DoS) Vulnerability
A vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-0101 was discovered whereby decompression of ACE file causes the scanner service to stop. The vulnerability can be exploited remotely by an attacker. A successful attack will result in denial-of-service of the antivirus engine.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-40837?
CVE-2021-40837 is a vulnerability affecting F-Secure antivirus engine before Capricorn update 2022-02-01_01, where decompression of ACE file causes the scanner service to stop.
How can CVE-2021-40837 be exploited?
CVE-2021-40837 can be exploited remotely by an attacker.
What is the severity of CVE-2021-40837?
CVE-2021-40837 has a severity rating of 5.3 (medium).
Which software versions are affected by CVE-2021-40837?
CVE-2021-40837 affects F-Secure Antivirus Engine versions before Capricorn update 2022-02-01_01, including F-Secure Atlant, F-Secure Internet Gatekeeper, F-Secure Linux Security, F-Secure Security Cloud, F-Secure Elements Endpoint Detection And Response, and F-Secure Elements Endpoint Protection.
How do I fix CVE-2021-40837?
To fix CVE-2021-40837, update your F-Secure Antivirus Engine to Capricorn update 2022-02-01_01 or later.