Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jemery Galindo

#38695of 56,330
7.5Total CVSS
Vulnerabilities · 1
PT-2021-4053
7.5
2021-04-14
Hivex · Hivex · CVE-2021-3504
**Name of the Vulnerable Software and Affected Versions** Hivex versions prior to 1.3.20 **Description** The issue is related to a lack of bounds check within the `hivex open` function, which can cause the library to read memory beyond its normal bounds or crash when processing a specially crafted Windows Registry (hive) file. This could allow a remote attacker to access confidential data or cause a denial of service, with the highest threat being to system availability. **Recommendations** For versions prior to 1.3.20, update to version 1.3.20 or later to resolve the issue. As a temporary workaround, consider restricting the use of the `hivex open` function until a patch is available. Avoid processing untrusted Windows Registry (hive) files with the affected library to minimize the risk of exploitation.