VYPR
Medium severity6.5NVD Advisory· Published Apr 14, 2022· Updated Jun 17, 2026

CVE-2021-40425

CVE-2021-40425

Description

An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. A specially-crafted executable can lead to denial of service. An attacker can issue an ioctl to trigger this vulnerability. An out-of-bounds read vulnerability exists in the IOCTL GetProcessCommand and B_03 of Webroot Secure Anywhere 21.4. An IOCTL_B03 request with specific invalid data causes a similar issue in the device driver WRCore_x64. An attacker can issue an ioctl to trigger this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:webroot:secureanywhere:21.4:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:webroot:secureanywhere:21.4:*:*:*:*:*:*:*
    • (no CPE)range: 21.4
    • (no CPE)range: 21.4

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.