CVE-2021-41352
published 2021-10-13CVE-2021-41352: SCOM Information Disclosure Vulnerability SCOM Information Disclosure Vulnerability
high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
2.79%
84.7th percentile
SCOM Information Disclosure Vulnerability
SCOM Information Disclosure Vulnerability
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | system_center_2012_r2_operations_manager | >= 7.1.0.0 < 7.1.10226.1413 | 7.1.10226.1413 |
| microsoft | system_center_2016_operations_manager | >= 7.2.0.0 < 7.2.12335.0 | 7.2.12335.0 |
| microsoft | system_center_2019_operations_manager | >= 10.0.0.0 < 10.19.10550.0 | 10.19.10550.0 |
| msrc | system_center_2012_r2_operations_manager | — | — |
| msrc | system_center_2016_operations_manager | — | — |
| msrc | system_center_2019_operations_manager | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
cvelistv57.5HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
SCOM Information Disclosure Vulnerability
vendor_msrc·2021-10-12·CVSS 7.5
CVE-2021-41352 [HIGH] SCOM Information Disclosure Vulnerability
SCOM Information Disclosure Vulnerability
FAQ: In what instances do I need to install the security update for this vulnerability?
This vulnerability only affects machines that have the SCOM web console installed. SCOM web console server machines should have this update installed to be protected from the vulnerability.
Do I need to install the update if my machine is not set up as a web console server?
No. Customers whose machines are not SCOM web console server machines do not need to install this update.
FAQ: What type of information could be disclosed by this vulnerability?
The type of information that could be disclosed if an attacker successfully exploited this vulnerability is file content.
System Center: System Center
Microsoft: Microsoft
Impact: Information Disclosure
Exploit
CVEList
SCOM Information Disclosure Vulnerability
cvelistv5·2021-10-13·CVSS 7.5
CVE-2021-41352 [HIGH] SCOM Information Disclosure Vulnerability
SCOM Information Disclosure Vulnerability
SCOM Information Disclosure Vulnerability
No detection rules found.
No public exploits indexed.
2021-10-13
Published