CVE-2021-42686 is an Integer Overflow vulnerability in Accops HyWorks Windows Client versions prior to 3.2.8.200, specifically within the IOCTL Handler 0x22001B. This high-severity vulnerability (CVSS 8.8) allows a local attacker to execute arbitrary code in kernel mode or cause a denial of service through memory corruption and OS crash by sending specially crafted I/O Request Packets. While there is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, the vulnerability has garnered some community and media attention, with one article detailing its broader implications for USB-over-network SDKs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.2.8.200CPE matchmatch criteria | cpe:2.3:a:accops:hyworks_windows_client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.