CVE-2021-43889
published 2021-12-15CVE-2021-43889: Microsoft Defender for IoT Remote Code Execution Vulnerability
PriorityP345high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.21%
80.5th percentile
Microsoft Defender for IoT Remote Code Execution Vulnerability
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | defender_for_iot | < 10.5.2 | 10.5.2 |
| microsoft | microsoft_defender_for_iot | >= 22.0.0 < 10.5.2 | 10.5.2 |
| msrc | microsoft_defender_for_iot | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_msrc7.2HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gjpx-9j96-m8gx: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42311, CVE-2021-42313, CVE-2021-423
ghsa_unreviewed·2021-12-16·CVSS 8.8
CVE-2021-42310 [HIGH] CWE-94 GHSA-gjpx-9j96-m8gx: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42311, CVE-2021-42313, CVE-2021-423
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42311, CVE-2021-42313, CVE-2021-42314, CVE-2021-42315, CVE-2021-43882, CVE-2021-43889.
GHSA
GHSA-p693-2vfq-fpvw: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42313, CVE-2021-423
ghsa_unreviewed·2021-12-16·CVSS 8.8
CVE-2021-42311 [HIGH] CWE-89 GHSA-p693-2vfq-fpvw: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42313, CVE-2021-423
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42313, CVE-2021-42314, CVE-2021-42315, CVE-2021-43882, CVE-2021-43889.
GHSA
GHSA-5x43-cm8r-v5wr: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-42310, CVE-2021-42311, CVE-2021-42313, CVE-2021-423
ghsa_unreviewed·2021-12-16·CVSS 8.1
CVE-2021-41365 [HIGH] CWE-89 GHSA-5x43-cm8r-v5wr: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-42310, CVE-2021-42311, CVE-2021-42313, CVE-2021-423
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-42310, CVE-2021-42311, CVE-2021-42313, CVE-2021-42314, CVE-2021-42315, CVE-2021-43882, CVE-2021-43889.
GHSA
GHSA-rwv9-gxrh-r43w: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
ghsa_unreviewed·2021-12-16·CVSS 8.8
CVE-2021-42313 [HIGH] CWE-89 GHSA-rwv9-gxrh-r43w: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-42314, CVE-2021-42315, CVE-2021-43882, CVE-2021-43889.
GHSA
GHSA-2p7j-4wf3-79hx: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
ghsa_unreviewed·2021-12-16·CVSS 8.8
CVE-2021-42314 [HIGH] CWE-94 GHSA-2p7j-4wf3-79hx: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-42313, CVE-2021-42315, CVE-2021-43882, CVE-2021-43889.
GHSA
GHSA-vf2w-cq9r-cwvw: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
ghsa_unreviewed·2021-12-16·CVSS 8.8
CVE-2021-43882 [HIGH] CWE-295 GHSA-vf2w-cq9r-cwvw: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-42313, CVE-2021-42314, CVE-2021-42315, CVE-2021-43889.
GHSA
GHSA-cgfp-rmx2-46w3: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
ghsa_unreviewed·2021-12-16·CVSS 8.8
CVE-2021-42315 [HIGH] CWE-94 GHSA-cgfp-rmx2-46w3: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-42313, CVE-2021-42314, CVE-2021-43882, CVE-2021-43889.
GHSA
GHSA-rpx5-2jw7-fmx4: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
ghsa_unreviewed·2021-12-16·CVSS 8.8
CVE-2021-43889 [HIGH] CWE-94 GHSA-rpx5-2jw7-fmx4: Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-423
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-41365, CVE-2021-42310, CVE-2021-42311, CVE-2021-42313, CVE-2021-42314, CVE-2021-42315, CVE-2021-43882.
Red Hat
kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper()
vendor_redhat·2024-08-26·CVSS 5.5
CVE-2024-43889 [MEDIUM] CWE-369 kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper()
kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper()
In the Linux kernel, the following vulnerability has been resolved:
padata: Fix possible divide-by-0 panic in padata_mt_helper()
We are hit with a not easily reproducible divide-by-0 panic in padata.c at
bootup time.
[ 10.017908] Oops: divide error: 0000 1 PREEMPT SMP NOPTI
[ 10.017908] CPU: 26 PID: 2627 Comm: kworker/u1666:1 Not tainted 6.10.0-15.el10.x86_64 #1
[ 10.017908] Hardware name: Lenovo ThinkSystem SR950 [7X12CTO1WW]/[7X12CTO1WW], BIOS [PSE140J-2.30] 07/20/2021
[ 10.017908] Workqueue: events_unbound padata_mt_helper
[ 10.017908] RIP: 0010:padata_mt_helper+0x39/0xb0
:
[ 10.017963] Call Trace:
[ 10.017968]
[ 10.018004] ? padata_mt_helper+0x39/0xb0
[ 10.018084] process_one_work+0x174/0x330
[ 10.018093] worker_thre
Microsoft
Microsoft Defender for IoT Remote Code Execution Vulnerability
vendor_msrc·2021-12-14·CVSS 7.2
CVE-2021-43889 [HIGH] Microsoft Defender for IoT Remote Code Execution Vulnerability
Microsoft Defender for IoT Remote Code Execution Vulnerability
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
An attacker needs to have support user privileges to be able to exploit this vulnerability.
FAQ: What version of Microsoft Defender for IoT has the update that protects from this vulnerability?
Version 10.5.2 and above.
What is the action required to take the update?
You need to update to the latest Microsoft Defender for IoT software version. See the Update the software version section of Manage the on-premises management console.
What is Microsoft Defender for IoT?
Microsoft Defender for IoT is a unified security solution for identifying IoT/OT devices, vulnerabilities, and threats. It enables you to secure you
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-12-15
Published