CVE-2021-1728
published 2021-02-25CVE-2021-1728: System Center Operations Manager Elevation of Privilege Vulnerability
PriorityP350high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.82%
76.3th percentile
System Center Operations Manager Elevation of Privilege Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | system_center_2019_operations_manager | >= 10.0.0.0 < publication | publication |
| microsoft | system_center_operations_manager | — | — |
| msrc | system_center_2019_operations_manager | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: usb: fix memory leak in smsc75xx_bind
vendor_redhat·2024-03-25·CVSS 5.5
CVE-2021-47171 [MEDIUM] CWE-402 kernel: net: usb: fix memory leak in smsc75xx_bind
kernel: net: usb: fix memory leak in smsc75xx_bind
In the Linux kernel, the following vulnerability has been resolved:
net: usb: fix memory leak in smsc75xx_bind
Syzbot reported memory leak in smsc75xx_bind().
The problem was is non-freed memory in case of
errors after memory allocation.
backtrace:
[] kmalloc include/linux/slab.h:556 [inline]
[] kzalloc include/linux/slab.h:686 [inline]
[] smsc75xx_bind+0x7a/0x334 drivers/net/usb/smsc75xx.c:1460
[] usbnet_probe+0x3b6/0xc30 drivers/net/usb/usbnet.c:1728
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 9) - Not affected
Package: kernel-rt (Red Hat
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44573 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] Two heap overflow vulnerabilities exist in oenSUSE libsolv through 13 Dec 2020 in the resolve_installed function at src/solver.c: line 1728 & 1766.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Microsoft
System Center Operations Manager Elevation of Privilege Vulnerability
vendor_msrc·2021-02-09·CVSS 8.8
CVE-2021-1728 [HIGH] System Center Operations Manager Elevation of Privilege Vulnerability
System Center Operations Manager Elevation of Privilege Vulnerability
FAQ: In what instances do I need to install the security update for this vulnerability?
This vulnerability only affects machines that have any of the following System Center 2019 - Operations Manager (SCOM) components installed:
Management Server
Microsoft Monitoring Agent
Gateway
Is there a prerequisite for installing the security update?
Yes. To apply this update, you must have Update Rollup 2 for System Center Operations Manager 2019 installed. See the How to obtain Update Rollup 2 for System Center Operations Manager 2019 section for instructions.
Do I need to install the update if I do not have "Enable Service log on" feature enabled?
No. This update is required if “Service Log on” or “Interactive Log on” is enab
GHSA
GHSA-fc98-w582-pwcx: System Center Operations Manager Elevation of Privilege Vulnerability
ghsa_unreviewed·2022-05-24
CVE-2021-1728 [HIGH] CWE-269 GHSA-fc98-w582-pwcx: System Center Operations Manager Elevation of Privilege Vulnerability
System Center Operations Manager Elevation of Privilege Vulnerability
No detection rules found.
No public exploits indexed.
2021-02-25
Published