关键信息 漏洞标识 CVE Identifier: CVE-2021-44207 漏洞描述 Description: The Acclaim USAHERDS web application 7.4.0.1 and earlier, builds prior to November 2021, used static ValidationKey and DecryptionKey values. CWE CWE enumeration: CWE-798 - Use of Hard-coded Credentials 影响 Impact: High - Knowledge of the ValidationKey and DecryptionKey can be used to achieve Remote Code Execution on the system that runs the application. 可利用性 Exploitability: Low - The ValidationKey and DecryptionKey would need to be obtained via a separate vulnerability or other channel. 技术细节 Technical Details: These keys are used to provide security for the application ViewState. A threat actor can trick the application server into deserializing maliciously crafted ViewState data. 发现者 Discovery Credits: Douglas Bienstock, Mandiant 披露时间线 Disclosure Timeline: 2021-11-23 - Issue reported to developer. Developer confirmed a patch had recently been released for the same issue. 参考链接 References: - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44207 - https://www.acclaimsytems.com/ - https://www.tnatc.org/