CVE-2021-44142
published 2022-02-21CVE-2021-44142: The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a…
PriorityP190high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
73.72%
99.4th percentile
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Affected
58 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | samba | < samba 2:4.16.0+dfsg-2 (bookworm) | samba 2:4.16.0+dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | azl3_samba_4.18.3-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_access | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_ibm_z_systems_eus | — | — |
| redhat | enterprise_linux_for_power_big_endian | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability exists in the parsing of EA metadata in the server daemon smbd when opening a file; monitor smbd process for anomalous out-of-bounds memory access triggered via extended file attributes (xattr) on shares with vfs_fruit enabled ↗
- →Exploitation vector is via specially crafted extended file attributes (EA/xattr); any remote write to xattrs on a Samba share with vfs_fruit configured should be treated as a high-risk event and monitored ↗
- →Monitor for smbd running as root executing unexpected child processes or spawning shells, as successful exploitation grants arbitrary code execution with root privileges ↗
- →Audit Samba share configurations for presence of vfs_fruit in vfs objects lines; installations NOT using vfs_fruit are unaffected — focus detection on hosts where fruit VFS module is active ↗
- →NAS devices are a high-priority detection/patching target as they commonly ship with older smbd versions (e.g. 4.9.5) and vfs_fruit enabled by default for Apple interoperability ↗
- ·Only Samba installations with the vfs_fruit VFS module configured are vulnerable; default configurations without vfs_fruit are not affected ↗
- ·Affected Samba versions are all releases prior to 4.13.17, 4.14.12, and 4.15.5; patched releases are 4.13.17, 4.14.12, and 4.15.5 ↗
- ·Removing the fruit VFS module from vfs objects lines is a vendor-suggested workaround but can severely impact macOS clients accessing the server ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vulncheck8.8HIGH
vendor_debian8.8HIGH
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
Informational: Impact of the Samba Vulnerability CVE-2021-44142 on PAN-OS
vendor_paloalto·2022-03-09·CVSS 8.8
CVE-2021-44142 [HIGH] CWE-125 Informational: Impact of the Samba Vulnerability CVE-2021-44142 on PAN-OS
Informational: Impact of the Samba Vulnerability CVE-2021-44142 on PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the Samba CVE-2021-44142 vulnerability.
Though PAN-OS software contains Samba packages, there isn’t a Samba server that runs in PAN-OS software that could enable an attacker to exploit this vulnerability, which means there are no scenarios that enable successful exploitation of this vulnerability in PAN-OS software.
To reiterate, there is no known security impact for this vulnerability on PAN-OS or Prisma Access appliances.
Affected products: PAN-OS, Prisma Access
Solution: No product updates are required for this vulnerability.
Microsoft
The Samba vfs_fruit module uses extended file attributes (EA xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions
vendor_msrc·2022-02-08·CVSS 8.8
CVE-2021-44142 [HIGH] CWE-125 The Samba vfs_fruit module uses extended file attributes (EA xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions
The Samba vfs_fruit module uses extended file attributes (EA xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd typically root.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure version
Ubuntu
Samba vulnerability
vendor_ubuntu·2022-02-03·CVSS 8.8
CVE-2021-44142 [HIGH] Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to crash when handled certain memory operations.
USN-5260-1 fixed a vulnerability in Samba. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
Ubuntu
Samba vulnerabilities
vendor_ubuntu·2022-02-01·CVSS 2.5
CVE-2022-0336 [LOW] Samba vulnerabilities
Title: Samba vulnerabilities
Summary: Several security issues were fixed in Samba.
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
Michael Hanselmann discovered that Samba incorrectly created directories.
In certain configurations, a remote attacker could possibly create a
directory on the server outside of the shared directory. (CVE-2021-43566)
Kees van Vloten discovered that Samba incorrectly handled certain aliased
SPN checks. A remote attacker could possibly use this issue to impersonate
services. (CVE-2022-0336)
Instructions: This update uses a new upstream release, whic
Ubuntu
Samba vulnerability
vendor_ubuntu·2022-02-01·CVSS 8.8
CVE-2021-44142 [HIGH] Samba vulnerability
Title: Samba vulnerability
Summary: Samba could be made to crash or run programs as an administrator if it
received specially crafted network traffic.
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution
vendor_redhat·2022-01-31·CVSS 8.8
CVE-2021-44142 [HIGH] CWE-787 samba: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution
samba: Out-of-bounds heap read/write vulnerability in VFS module vfs_fruit allows code execution
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
An out-of-bounds heap read write vulnerability was found in Samba. Due to a boundary error when processing EA metadata while opening files in smbd within the VFS Samba module (vfs_fruit), a remote attacker with ab
Debian
CVE-2021-44142: samba - The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide ...
vendor_debian·2021·CVSS 8.8
CVE-2021-44142 [HIGH] CVE-2021-44142: samba - The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide ...
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Scope: local
bookworm: resolved (fixed in 2:4.16.0+dfsg-2)
bullseye: resolved (fixed in 2:4.13.13+dfsg-1~deb11u3)
forky: resolved (fixed in 2:4.16.0+dfsg-2)
sid: resolved (fixed in 2:4.16.0+dfsg-2)
trixie: resolved (fixed in 2:4.16.0+dfsg-2)
GHSA
GHSA-mpfw-9wp5-hfff: The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "
ghsa_unreviewed·2022-02-22
CVE-2021-44142 [HIGH] CWE-125 GHSA-mpfw-9wp5-hfff: The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
OSV
CVE-2021-44142: The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "
osv·2022-02-21·CVSS 8.8
CVE-2021-44142 [HIGH] CVE-2021-44142: The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
OSV
samba vulnerability
osv·2022-02-03·CVSS 8.8
CVE-2021-44142 [HIGH] samba vulnerability
samba vulnerability
USN-5260-1 fixed a vulnerability in Samba. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
OSV
samba vulnerabilities
osv·2022-02-01·CVSS 2.5
CVE-2021-44142 [LOW] samba vulnerabilities
samba vulnerabilities
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
Michael Hanselmann discovered that Samba incorrectly created directories.
In certain configurations, a remote attacker could possibly create a
directory on the server outside of the shared directory. (CVE-2021-43566)
Kees van Vloten discovered that Samba incorrectly handled certain aliased
SPN checks. A remote attacker could possibly use this issue to impersonate
services. (CVE-2022-0336)
OSV
samba vulnerability
osv·2022-02-01·CVSS 8.8
CVE-2021-44142 [HIGH] samba vulnerability
samba vulnerability
Orange Tsai discovered that the Samba vfs_fruit module incorrectly handled
certain memory operations. A remote attacker could use this issue to cause
Samba to crash, resulting in a denial of service, or possibly execute
arbitrary code as root. (CVE-2021-44142)
VulnCheck
Samba Samba Out-of-bounds Read
vulncheck·2021·CVSS 8.8
CVE-2021-44142 [HIGH] Samba Samba Out-of-bounds Read
Samba Samba Out-of-bounds Read
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.
Affected: Samba Samba
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/2024-07/aa24-207a-dprk-cyber-grou
No detection rules found.
No public exploits indexed.
Checkpoint
7th February– Threat Intelligence Report
blogs_checkpoint·2022-02-07
CVE-2022-20699 7th February– Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 7th February– Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th February, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
A significant Ransomware attack has disrupted operations of oil port terminals in Belgium, Germany and in the Netherlands, affecting at least 17 ports and resulting in difficulties loading and unloading refined product cargoes. The BlackCat cybercrime group is suspected to be the group behind the attack.
Check Point Harmo
Trendmicro
This Week in Security News - February 4th, 2022
blogs_trendmicro·2022-02-04·CVSS 8.8
[HIGH] This Week in Security News - February 4th, 2022
Ransomware
# This Week in Security News - February 4, 2022
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. Learn about the Samba vulnerability discovered by Trend Micro the White House’s warning of Russian hacks as tensions with Ukraine grow.
By: Jon Clay
2022/02/04
Read time: ( words)
Save to Folio
Welcome to our weekly roundup, where we share what you need to know about cybersecurity news and events that happened over the past few days. This week, learn about the Samba vulnerability discovered by Trend Micro. Also, read about the White House’s warning of Russian hacks as tensions with Ukraine grow.
Read on:
The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
An earlier ver
Trendmicro
The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
blogs_trendmicro·2022-02-02·CVSS 8.8
CVE-2021-44142 [HIGH] The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Ausnutzung von Schwachstellen
## The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Information on the latest Samba vulnerability and how to protect systems against the threats that can exploit it.
By: Trend Micro Feb 02, 2022 Read time: ( words)
Save to Folio
Update as of February 8, 2022: To help identify vulnerable endpoints and/or servers, you may use our recently published assessment tool to scan for the Samba vulnerability .
An earlier version of an out-of-bounds (OOB) vulnerability in Samba was disclosed via Trend Micro Zero Day Initiative’s ( ZDI ) Pwn2Own Austin 2021 . ZDI looked further into the security gap and found more variants of the vulnerability after the event and subsequently disclosed the findings to the company. While we have not seen any active at
Trendmicro
The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
blogs_trendmicro·2022-02-02·CVSS 8.8
CVE-2021-44142 [HIGH] The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Exploits & Vulnerabilities
## The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Information on the latest Samba vulnerability and how to protect systems against the threats that can exploit it.
By: Trend Micro 2022/02/02 Read time: ( words)
Save to Folio
Update as of February 8, 2022: To help identify vulnerable endpoints and/or servers, you may use our recently published assessment tool to scan for the Samba vulnerability .
An earlier version of an out-of-bounds (OOB) vulnerability in Samba was disclosed via Trend Micro Zero Day Initiative’s ( ZDI ) Pwn2Own Austin 2021 . ZDI looked further into the security gap and found more variants of the vulnerability after the event and subsequently disclosed the findings to the company. While we have not seen any active attacks
Trendmicro
The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
blogs_trendmicro·2022-02-02·CVSS 8.8
CVE-2021-44142 [HIGH] The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Exploits y vulnerabilidades
## The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Information on the latest Samba vulnerability and how to protect systems against the threats that can exploit it.
By: Trend Micro Feb 02, 2022 Read time: ( words)
Save to Folio
Update as of February 8, 2022: To help identify vulnerable endpoints and/or servers, you may use our recently published assessment tool to scan for the Samba vulnerability .
An earlier version of an out-of-bounds (OOB) vulnerability in Samba was disclosed via Trend Micro Zero Day Initiative’s ( ZDI ) Pwn2Own Austin 2021 . ZDI looked further into the security gap and found more variants of the vulnerability after the event and subsequently disclosed the findings to the company. While we have not seen any active atta
Trendmicro
The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
blogs_trendmicro·2022-02-02·CVSS 8.8
CVE-2021-44142 [HIGH] The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Exploits & Vulnerabilities
# The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Information on the latest Samba vulnerability and how to protect systems against the threats that can exploit it.
By: Trend Micro
2022/02/02
Read time: ( words)
Save to Folio
Update as of February 8, 2022: To help identify vulnerable endpoints and/or servers, you may use our recently published assessment tool to scan for the Samba vulnerability.
An earlier version of an out-of-bounds (OOB) vulnerability in Samba was disclosed via Trend Micro Zero Day Initiative’s (ZDI) Pwn2Own Austin 2021. ZDI looked further into the security gap and found more variants of the vulnerability after the event and subsequently disclosed the findings to the company. While we have not seen any active attacks exp
Trendmicro
La vulnerabilidad de Samba: qué es CVE-2021-44142 y cómo solucionarlo
blogs_trendmicro·2022-02-02·CVSS 8.8
CVE-2021-44142 [HIGH] La vulnerabilidad de Samba: qué es CVE-2021-44142 y cómo solucionarlo
## La vulnerabilidad de Samba: qué es CVE-2021-44142 y cómo solucionarlo
Información sobre la última vulnerabilidad de Samba y cómo proteger los sistemas contra las amenazas que pueden aprovecharla.
By: Trend Micro Feb 02, 2022 Read time: ( words)
Save to Folio
Por: Trend Micro
Una versión anterior de una vulnerabilidad fuera de los límites (OOB) en Samba fue revelada a través de Pwn2Own Austin 2021 de Trend Micro Zero Day Initiative ( ZDI ). ZDI investigó más a fondo la brecha de seguridad y encontró más variantes de la vulnerabilidad después del evento y posteriormente reveló los hallazgos a la empresa. Aunque no hemos visto ningún ataque activo que explote esta vulnerabilidad, CVE-2021-44142 recibió una calificación CVSS de 9,9 de las tres variantes reportadas. Si se abusa de esta
Trendmicro
The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
blogs_trendmicro·2022-02-02·CVSS 8.8
CVE-2021-44142 [HIGH] The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Sfruttamento vulnerabilità
## The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Information on the latest Samba vulnerability and how to protect systems against the threats that can exploit it.
By: Trend Micro Feb 02, 2022 Read time: ( words)
Save to Folio
Update as of February 8, 2022: To help identify vulnerable endpoints and/or servers, you may use our recently published assessment tool to scan for the Samba vulnerability .
An earlier version of an out-of-bounds (OOB) vulnerability in Samba was disclosed via Trend Micro Zero Day Initiative’s ( ZDI ) Pwn2Own Austin 2021 . ZDI looked further into the security gap and found more variants of the vulnerability after the event and subsequently disclosed the findings to the company. While we have not seen any active attac
Trendmicro
The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
blogs_trendmicro·2022-02-02·CVSS 8.8
CVE-2021-44142 [HIGH] The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Exploits & Vulnerabilities
## The Samba Vulnerability: What is CVE-2021-44142 and How to Fix It
Information on the latest Samba vulnerability and how to protect systems against the threats that can exploit it.
By: Trend Micro Feb 02, 2022 Read time: ( words)
Save to Folio
Update as of February 8, 2022: To help identify vulnerable endpoints and/or servers, you may use our recently published assessment tool to scan for the Samba vulnerability .
An earlier version of an out-of-bounds (OOB) vulnerability in Samba was disclosed via Trend Micro Zero Day Initiative’s ( ZDI ) Pwn2Own Austin 2021 . ZDI looked further into the security gap and found more variants of the vulnerability after the event and subsequently disclosed the findings to the company. While we have not seen any active attac
https://bugzilla.samba.org/show_bug.cgi?id=14914https://kb.cert.org/vuls/id/119678https://security.gentoo.org/glsa/202309-06https://www.samba.org/samba/security/CVE-2021-44142.htmlhttps://www.zerodayinitiative.com/blog/2022/2/1/cve-2021-44142-details-on-a-samba-code-execution-bug-demonstrated-at-pwn2own-austinhttps://bugzilla.samba.org/show_bug.cgi?id=14914https://kb.cert.org/vuls/id/119678https://security.gentoo.org/glsa/202309-06https://www.kb.cert.org/vuls/id/119678https://www.samba.org/samba/security/CVE-2021-44142.htmlhttps://www.zerodayinitiative.com/blog/2022/2/1/cve-2021-44142-details-on-a-samba-code-execution-bug-demonstrated-at-pwn2own-austin
2022-02-21
Published
Exploited in the wild