Junglewise Threat Intelligence

CVE-2021-27852: Checkbox Survey Deserialization of Untrusted Data Vulnerability

CVE-2021-27852 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-11

Executive brief

A deserialization of untrusted data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. The issue affects versions prior to 7, which are considered end-of-life.

Affected products

  • Checkbox Survey versions prior to 7

Timeline

  • 2021-05-27: disclosed: NVD Published Date
  • 2022-04-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog