Rewterz

Rewterz Threat Advisory – CVE-2021-26420 – Microsoft SharePoint Remote Code Execution Vulnerability

June 24, 2021
Rewterz

Rewterz Threat Alert – FormBook Malware – Active IOCs

June 24, 2021

Rewterz Threat Advisory – ICS: Advantech WebAccess HMI Designer

Severity

High

Analysis Summary

CVE-2021-33000

Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution.

CVE-2021-33002

Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code.

CVE-2021-33004

The affected product is vulnerable to memory corruption conditions due to a lack of proper validation of user-supplied files, which may allow an attacker to execute arbitrary code.

Impact

  • Unauthorized Access
  • Code Execution

Affected Vendors

Advantech

Affected Products

WebAccess HMI Designer Versions 2.1.9.95 and prior

Remediation

Refer to vendor advisory for the complete list of affected products and their respective patches at https://us-cert.cisa.gov/ics/advisories/icsa-21-173-01

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.