CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2021-20722: scansnap manager before 7.0l20 (exclusive); +1 more affected products

CVE-2021-20722. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.0044 (percentile 0.36088), scored 2026-10-06.

Affected technology

scansnap manager · before 7.0l20 (exclusive)
fujitsu

The installers of ScanSnap Manager and the Software Download Installer · The installers of ScanSnap Manager prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe
FUJITSU LIMITED and PFU LIMITED

Description’s affected range: prior to versions V7.0L20 and the Software Download Installer prior to WinSSInst2JP.exe and WinSSInst2iX1500JP.exe allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Local · No privileges required · User interaction required

Attack conditions (Source advisory, CVSS 3.1): Local · No privileges required · User interaction required

What an attacker can do

An attacker can gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory. NVD’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high. Source advisory’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-427
CCR priority
31.3 /100 (P4)
CVSS 3.1
7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H · NVD
EPSS
0.0044 · percentile 0.36088 · 2026-10-06
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2021-20722.html