go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

CHANGING Inc. TSSServiSignAdapter Windows Versions - Improper Input Validation

TVN ID TVN-202105006
CVE ID CVE-2021-37909
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products CHANGING Inc. TSSServiSignAdapter Windows Versions <= 1.0.20.0316
Description WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permissions thus perform hijack attacks to execute arbitrary code.
Solution Update to version 1.0.21.0520
Credit Angelboy
Public Date 2021-09-16
Top