CVE-2021-42258criticalunder attackransomwareCWE-89

CVE-2021-42258

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 74%
from disclosure to weapon0 days
Published on NVDOct 22
metasploitOct 22
CISA KEV+12d
exploitation probability
74%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2021-11-17

Apply updates per vendor instructions.

In short

BQE BillQuick Web Suite versions before 22.0.9.1 contain a SQL injection vulnerability in the login form that allows attackers to execute arbitrary code on the server without needing valid credentials. This critical flaw was actively exploited in October 2021 to deploy ransomware.

Technical detail

Unauthenticated SQL injection exists in the txtID (username) parameter of BQE BillQuick Web Suite 2018-2021 (before 22.0.9.1). Successful exploitation enables arbitrary SQL command execution and code execution via xp_cmdshell under the MSSQLSERVER$ service account, with no authentication required.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include the ability to execute arbitrary code as MSSQLSERVER$ via xp_cmdshell.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a