Record summary

CVE-2021-1647 has a selected CVSS score of 7.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2021-1647 in KEV.

Description

Microsoft Defender Remote Code Execution Vulnerability

Description source: GitHub Advisory

Exploitation context

Known exploitation

CISA KEV
Listed · Nov 3, 2021 · CISA
VulnCheck KEV
Listed · Jan 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 24, 2024 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus
CISAVersion data not supplied
CVE ListVersion range not suppliedaffected

Microsoft System Center 2012 Endpoint Protection

Browse Microsoft / Microsoft System Center 2012 Endpoint Protection
CVE ListVersion range not suppliedaffected

Microsoft System Center 2012 R2 Endpoint Protection

Browse Microsoft / Microsoft System Center 2012 R2 Endpoint Protection
CVE ListVersion range not suppliedaffected

Microsoft System Center Endpoint Protection

Browse Microsoft / Microsoft System Center Endpoint Protection
CVE ListVersion range not suppliedaffected
CVE ListVersion range not suppliedaffected

Proofs of concept

1

Repository PoCs

GitHubfindcool/cve-2021-1647Repository PoCby findcoolStars: 1Not analyzed2 files

22.2 KiB

GitHub

PoC details

References

4