CVE-2021-32559
Last modified
CVE-2021-32559 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mhammond | Pywin32 | < 301 |
References
- https://github.com/mhammond/pywin32/issues/1700Patch, Third Party Advisory
- https://github.com/mhammond/pywin32/pull/1701Third Party Advisory
- https://github.com/mhammond/pywin32/releasesRelease Notes, Third Party Advisory
- https://github.com/mhammond/pywin32/issues/1700Patch, Third Party Advisory
- https://github.com/mhammond/pywin32/pull/1701Third Party Advisory
- https://github.com/mhammond/pywin32/releasesRelease Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-32559?
How severe is CVE-2021-32559?
How do I fix CVE-2021-32559?
Are you affected by CVE-2021-32559?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
