CVE-2021-27852
CRITICAL KEVCheckbox Survey <7 - RCE
Title source: llmDescription
Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.
Scores
CVSS v3
9.8
EPSS
0.2555
EPSS Percentile
96.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Intel
CISA KEV
2022-04-11
VulnCheck KEV
2022-04-11
InTheWild.io
2021-07-27
ENISA EUVD
EUVD-2021-14590
Classification
CWE
CWE-502
Status
published
Affected Products (1)
checkbox/survey
< 7.0
Timeline
Published
May 27, 2021
KEV Added
Apr 11, 2022
Tracked Since
Feb 18, 2026