Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters.
                
            References
                    | Link | Resource | 
|---|---|
| https://habr.com/ru/company/pm/blog/579328/ | Exploit Third Party Advisory | 
| https://news.drweb.ru/show/?i=14180&lng=ru | Vendor Advisory | 
| https://habr.com/ru/company/pm/blog/579328/ | Exploit Third Party Advisory | 
| https://news.drweb.ru/show/?i=14180&lng=ru | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
History
                    21 Nov 2024, 05:59
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://habr.com/ru/company/pm/blog/579328/ - Exploit, Third Party Advisory | |
| References | () https://news.drweb.ru/show/?i=14180&lng=ru - Vendor Advisory | 
06 Oct 2021, 13:41
| Type | Values Removed | Values Added | 
|---|---|---|
| References | (MISC) https://habr.com/ru/company/pm/blog/579328/ - Exploit, Third Party Advisory | |
| References | (MISC) https://news.drweb.ru/show/?i=14180&lng=ru - Vendor Advisory | |
| CWE | CWE-427 | |
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 4.4
         v3 : 7.8  | 
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:drweb:security_space:12.5.2.4160:*:*:*:*:*:*:*  | 
24 Sep 2021, 16:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2021-09-24 16:15
Updated : 2024-11-21 05:59
NVD link : CVE-2021-28130
Mitre link : CVE-2021-28130
CVE.ORG link : CVE-2021-28130
JSON object : View
Products Affected
                drweb
- security_space
 
microsoft
- windows
 
CWE
                
                    
                        
                        CWE-427
                        
            Uncontrolled Search Path Element
