CVE-2021-44750: Arbitrary Code Execution
Published Mar 9, 2022
·Updated
An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special configuration file, which when run by administrator can execute any commands.
Affected Software
6 affected components
F-Secure Client Security
F-Secure Countercept
F-Secure Elements
F-Secure Email and Server Security
F-Secure Server Security
Microsoft Windows
Remediation
Information
MITIGATION FACTOR
User interaction is required prior to exploitation. Administrative privileges is required to run arbitrary commands in the system.
Event History
Mar 9, 2022
CVE Published
via MITRE·11:38 AM
Data Sourced
via MITRE·11:38 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-44750?
CVE-2021-44750 is an arbitrary code execution vulnerability found in the F-Secure Support Tool.
2
How does CVE-2021-44750 work?
A standard user can create a special configuration file that, when executed by an administrator, can run any commands.
3
Which software products are affected by CVE-2021-44750?
F-Secure Client Security, F-Secure Countercept, F-Secure Elements, F-Secure Email And Server Security, and F-Secure Server Security are affected by CVE-2021-44750.
4
What is the severity of CVE-2021-44750?
CVE-2021-44750 has a severity rating of 7.3 (High).
5
How can I fix CVE-2021-44750?
Apply the necessary updates and patches provided by F-Secure to mitigate CVE-2021-44750.