Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-24032

18
FAUCET Score

CVE-2021-24032 affects Zstandard versions 1.4.1 through 1.4.8, where an incomplete fix for a prior vulnerability allowed output files to be momentarily readable or writable by unauthorized parties due to default permissions before being restricted. This local vulnerability has a CVSS score of 4.7 (Medium), indicating high confidentiality impact with low privileges and high attack complexity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing, with minimal community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.4.1, < 1.4.9CPE matchmatch criteria
cpe:2.3:a:facebook:zstandard:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.35%
Probability of exploitation in next 30 days
EPSS Percentile
27.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0035 is in the 76th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (26)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 19021-16820Fixed in: 1.4.9-1
microsoftpatch availablevia msrc
Product: 19022-16823Fixed in: 16.2.10-3
microsoftpatch availablevia msrc
Product: 19814-17086Fixed in: 16.2.10-3
microsoftpatch availablevia msrc
Product: 19023-17084Fixed in: 18.2.2-5
microsoftpatch availablevia msrc
Product: 19666-17084Fixed in: 18.2.2-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 16.2.10-3
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 1.4.9-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 1.4.9-1
microsoftpatch availablevia msrc
Product: cm1 zstd 1.4.9-1 on CBL Mariner 1.0Fixed in: 1.4.9-1
microsoftpatch availablevia msrc
Product: cbl2 ceph 16.2.10-3 on CBL Mariner 2.0Fixed in: 16.2.10-3
microsoftpatch availablevia msrc
Product: cbl2 ceph 16.2.10-7 on CBL Mariner 2.0Fixed in: 16.2.10-3
microsoftpatch availablevia msrc
Product: azl3 ceph 18.2.2-5 on Azure Linux 3.0Fixed in: 18.2.2-5
microsoftpatch availablevia msrc
Product: azl3 ceph 18.2.2-8 on Azure Linux 3.0Fixed in: 18.2.2-5
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 16.2.10-3
redhatpatch availablevia redhat_api
Product: Red Hat AMQ Streams 2.7.0
View patch
capnprotovendor investigatingvia llm_extracted
gcpvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
kongvendor investigatingvia llm_extracted
openwrtvendor investigatingvia llm_extracted
proxmoxvendor investigatingvia llm_extracted
redhatvendor investigatingvia redhat_api
Product: Red Hat Ceph Storage 3Fixed in: ceph
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: zstd
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: libzstd
redhatno patchvia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: rox

Vendor Advisories (10)

microsoft2024-Dec/CVE-2021-24032

CVE-2021-24032

Dec 10, 2024
microsoft2021-Jul/CVE-2021-24032

CVE-2021-24032

Jul 13, 2021
proxmoxllm-proxmox-202933dd58ce3ba3CRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
kongllm-kong-7933c1edf7557da9CRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
hanwhallm-hanwha-0b610f8bff10f748CRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
capnprotollm-capnproto-5feb06313b602a85HIGH

ctrlX Multiple Vulnerabilities

Apr 23, 2021
openwrtllm-openwrt-b814c0e383a6a281CRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
gcpllm-gcp-01a119d0ea3516faCRITICAL

ctrlX Multiple Vulnerabilities

Apr 23, 2021
microsoft2021-Mar/CVE-2021-24032Moderate

Beginning in v1.4.1 and prior to v1.4.9 due to an incomplete fix for CVE-2021-24031 the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.

Mar 9, 2021
redhatCVE-2021-24032Low

zstd: Race condition allows attacker to access world-readable destination file

Feb 11, 2021

References

bugs.debian.org / cgi-bin/bugreport.cgi
PatchThird Party Advisory
github.com / facebook/zstd/issues/2491
Issue TrackingPatchThird Party Advisory
facebook.com / security/advisories/cve-2021-24032
Third Party Advisory