CVE-2021-43899: Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability

Overview

Severity
Critical (CVSS 9.8)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Remote Code Execution
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2021-Dec
Released
2021-12-14
EPSS Score
0.88% (percentile: 75.4%)

FAQ

What firmware version of the Microsoft 4K Wireless Display Adapter has the update that protects from this vulnerability? All firmware versions of the Microsoft 4K Wireless Display Adapter that are 3.9520.47 and higher are protected from this vulnerability. How do I ensure my Microsoft 4K Wireless Display Adapter device has the update? You will need to install the Microsoft Wireless Display Adapter app from the Microsoft Store onto a system connected to the Microsoft 4K Wireless Display Adapter. Once installed, use the Update & security section of the app to download and install the latest firmware. How could an attacker exploit this vulnerability? An unauthenticated attacker on the same network as the Microsoft 4K Display Adapter could send specially crafted packets to a vulnerable device.

Affected Products (1)

Device

  • Microsoft 4K Wireless Display Adapter

Security Updates (1)

Acknowledgments

<a href="https://www.linkedin.com/in/han-yong-lim-312b88a7/">Han Yong Lim</a> with <a href="https://www.dbschenker.com/">DB Schenker</a>

Revision History

  • 2021-12-14: Information published.