Q4. Refer to the CVE and NVD search results of CVE-2021-20616 as in the following figure. Q4. a) List 3 important information about CVE-2021-20616 that you can extract from the diagram above? Q4. b) What type of malware is affecting the victim’s computer? Q4. c) What does the malware do in this attack?

Database System Concepts
7th Edition
ISBN:9780078022159
Author:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Chapter1: Introduction
Section: Chapter Questions
Problem 1PE
icon
Related questions
Question

Q4. Refer to the CVE and NVD search results of CVE-2021-20616 as in the following figure.

Q4. a) List 3 important information about CVE-2021-20616 that you can extract from the diagram above?

Q4. b) What type of malware is affecting the victim’s computer?

Q4. c) What does the malware do in this attack?

Vulnerability Details : CVE-2021-20616
Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver. 16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an
unspecified directory.
Publish Date: 2021-01-13 Last Update Date: 2022-05-03
Scroll To ▾ Comments
External Links
Collapse All Expand All Select Select&Copy
Search Twitter Search YouTube Search Google
- CVSS Scores & Vulnerability Types
CVSS Score
4.4
Partial (There is considerable informational disclosure.)
Confidentiality Impact
Integrity Impact
Partial (Modification of some system files or information is possible, but the attacker does not have control over what can be modified, or the scope of
what the attacker can affect is limited.)
Availability Impact
Partial (There is reduced performance or interruptions in resource availability.)
Access Complexity
Medium (The access conditions are somewhat specialized. Some preconditions must be satistified to exploit)
Not required (Authentication is not required to exploit the vulnerability.)
Authentication
None
Gained Access
Vulnerability Type(s)
CWE ID
Gain privileges
427
- Products Affected By CVE-2021-20616
# Product Type Vendor
Product
Version Update Edition Language
1 Application Skygroup Skysea Client View *
Version Details Vulnerabilities
- Number Of Affected Versions By Product
Transcribed Image Text:Vulnerability Details : CVE-2021-20616 Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver. 16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. Publish Date: 2021-01-13 Last Update Date: 2022-05-03 Scroll To ▾ Comments External Links Collapse All Expand All Select Select&Copy Search Twitter Search YouTube Search Google - CVSS Scores & Vulnerability Types CVSS Score 4.4 Partial (There is considerable informational disclosure.) Confidentiality Impact Integrity Impact Partial (Modification of some system files or information is possible, but the attacker does not have control over what can be modified, or the scope of what the attacker can affect is limited.) Availability Impact Partial (There is reduced performance or interruptions in resource availability.) Access Complexity Medium (The access conditions are somewhat specialized. Some preconditions must be satistified to exploit) Not required (Authentication is not required to exploit the vulnerability.) Authentication None Gained Access Vulnerability Type(s) CWE ID Gain privileges 427 - Products Affected By CVE-2021-20616 # Product Type Vendor Product Version Update Edition Language 1 Application Skygroup Skysea Client View * Version Details Vulnerabilities - Number Of Affected Versions By Product
Expert Solution
steps

Step by step

Solved in 3 steps

Blurred answer
Knowledge Booster
Database Functions
Learn more about
Need a deep-dive on the concept behind this application? Look no further. Learn more about this topic, computer-science and related others by exploring similar questions and additional content below.
Similar questions
  • SEE MORE QUESTIONS
Recommended textbooks for you
Database System Concepts
Database System Concepts
Computer Science
ISBN:
9780078022159
Author:
Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:
McGraw-Hill Education
Starting Out with Python (4th Edition)
Starting Out with Python (4th Edition)
Computer Science
ISBN:
9780134444321
Author:
Tony Gaddis
Publisher:
PEARSON
Digital Fundamentals (11th Edition)
Digital Fundamentals (11th Edition)
Computer Science
ISBN:
9780132737968
Author:
Thomas L. Floyd
Publisher:
PEARSON
C How to Program (8th Edition)
C How to Program (8th Edition)
Computer Science
ISBN:
9780133976892
Author:
Paul J. Deitel, Harvey Deitel
Publisher:
PEARSON
Database Systems: Design, Implementation, & Manag…
Database Systems: Design, Implementation, & Manag…
Computer Science
ISBN:
9781337627900
Author:
Carlos Coronel, Steven Morris
Publisher:
Cengage Learning
Programmable Logic Controllers
Programmable Logic Controllers
Computer Science
ISBN:
9780073373843
Author:
Frank D. Petruzella
Publisher:
McGraw-Hill Education