cbcvebase.
CVE-2021-1386
published 2021-04-08

CVE-2021-1386: A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpoints Windows Connector, ClamAV for…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.28%
20.2th percentile
A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpoints Windows Connector, ClamAV for Windows, and Immunet could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected Windows system. To exploit this vulnerability, the attacker would need valid credentials on the system. The vulnerability is due to insufficient validation of directory search paths at run time. An attacker could exploit this vulnerability by placing a malicious DLL file on an affected system. A successful exploit could allow the attacker to execute arbitrary code with SYSTEM privileges.

Affected

8 ranges
VendorProductVersion rangeFixed in
ciscoadvanced_malware_protection_for_endpoints< 7.3.157.3.15
ciscoadvanced_malware_protection_for_endpoints_windows_connector_clamav_for_windows_a
ciscocisco_amp_for_endpoints
ciscoclamav< 0.103.20.103.2
ciscoimmunet< 7.4.07.4.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_clamav_0.103.2-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
cisa7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.