Security readout for executives and security teams
Plain-English summary
A local low-privileged user can crash ForeScout SecureConnector by abusing an installation path value. This affects SecureConnector 11.0.4.1024. The business concern is endpoint security service disruption on systems where untrusted local users can interact with the affected connector.
Executive priority
Treat as a moderate operational risk. Prioritize affected shared or high-value endpoints first, because disruption of a security connector can reduce visibility or control even without confirmed remote exploitation.
Technical view
The source describes a local buffer overflow condition: excessive characters written into installationPath overwrite the stack cookie and crash the SecureConnector local service. The published CVSS is 6.1, local attack vector, low complexity, low privileges, no user interaction. The description names denial of service, while the vector lists high confidentiality and low integrity impact.
Likely exposure
Exposure appears limited to hosts running ForeScout SecureConnector 11.0.4.1024, especially shared workstations, kiosks, labs, or servers where low-privileged local users have access.
Exploitation context
The bundle does not show active exploitation, public exploit availability, or KEV listing. Attack prerequisites are local access and low privileges. Evidence is incomplete on practical exploitability beyond service crash.
Researcher notes
The record’s description emphasizes local service denial of service, but the CVSS vector includes confidentiality and integrity impacts. No CWE, patch version, exploit evidence, or detailed vendor remediation is included in the provided bundle.
Mitigation direction
- Identify endpoints running SecureConnector 11.0.4.1024.
- Check ForeScout or official advisory guidance for fixed versions or compensating controls.
- Reduce unnecessary local user access on affected endpoints.
- Review permissions around SecureConnector installation and configuration paths.
- Monitor for unexpected SecureConnector service crashes.
Validation and detection
- Inventory SecureConnector versions across managed endpoints.
- Confirm whether SecureConnector 11.0.4.1024 is present.
- Review endpoint logs for recurring SecureConnector service crashes.
- Verify local permissions on SecureConnector installation and configuration locations.
- Do not validate by attempting overflow-style crash testing in production.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-36724 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.1 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N1.84.2Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.1MediumVector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://www.gov.il/en/departments/faq/cve_advisoriesCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
