Skip to content
COOEY

EXPOSURES › CVE-2021-27852

CVE-2021-27852

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-27852 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Checkbox Survey's CheckboxWeb.dll contained a deserialization of untrusted data vulnerability allowing unauthenticated remote code execution.

Checkbox Survey shipped with a deserialization of untrusted data flaw in CheckboxWeb.dll that permitted unauthenticated remote attackers to execute arbitrary code. DIB organizations must ensure Checkbox Survey is patched or replaced, as this vulnerability was actively exploited in the wild and represents a severe compliance risk under NIST 800-171 for systems handling CUI.

Shame score — Checkbox Survey shipped with a known, actively exploited remote code execution vulnerability that attackers could leverage without authentication, indicating a severe failure in patch management and secure software development.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.