EXPOSURES › CVE-2021-27852
CVE-2021-27852
HIGH ⌖ ON CISA KEV · EXPLOITEDCheckbox Survey's CheckboxWeb.dll contained a deserialization of untrusted data vulnerability allowing unauthenticated remote code execution.
Checkbox Survey shipped with a deserialization of untrusted data flaw in CheckboxWeb.dll that permitted unauthenticated remote attackers to execute arbitrary code. DIB organizations must ensure Checkbox Survey is patched or replaced, as this vulnerability was actively exploited in the wild and represents a severe compliance risk under NIST 800-171 for systems handling CUI.
Shame score — Checkbox Survey shipped with a known, actively exploited remote code execution vulnerability that attackers could leverage without authentication, indicating a severe failure in patch management and secure software development.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.