CVE-2021-32559
Last modified
CVE-2021-32559 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mhammond | Pywin32 | < 301 |
References
- https://github.com/mhammond/pywin32/issues/1700Patch, Third Party Advisory
- https://github.com/mhammond/pywin32/pull/1701Third Party Advisory
- https://github.com/mhammond/pywin32/releasesRelease Notes, Third Party Advisory
- https://github.com/mhammond/pywin32/issues/1700Patch, Third Party Advisory
- https://github.com/mhammond/pywin32/pull/1701Third Party Advisory
- https://github.com/mhammond/pywin32/releasesRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-32559?
How severe is CVE-2021-32559?
How do I fix CVE-2021-32559?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32553It was discovered that read_file() in apport/hookutils.py wo…5.5
- CVE-2021-32554It was discovered that read_file() in apport/hookutils.py wo…5.5
- CVE-2021-32555It was discovered that read_file() in apport/hookutils.py wo…5.5
- CVE-2021-32556It was discovered that the get_modified_conffiles() function…3.3
- CVE-2021-32557It was discovered that the process_report() function in data…7.1
- CVE-2021-32558An issue was discovered in Sangoma Asterisk 13.x before 13.3…7.5
- CVE-2021-3256KuaiFanCMS V5.x contains an arbitrary file read vulnerabilit…6.5
- CVE-2021-32560The Logging subsystem in OctoPrint before 1.6.0 has incorrec…6.5
- CVE-2021-32561OctoPrint before 1.6.0 allows XSS because API error messages…6.1
- CVE-2021-32563An issue was discovered in Thunar before 4.16.7 and 4.17.x b…9.8
- CVE-2021-32565Invalid values in the Content-Length header sent to Apache T…7.5
- CVE-2021-32566Improper Input Validation vulnerability in HTTP/2 of Apache …7.5
Are you affected by CVE-2021-32559?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
