CVE-2021-42694, also known as "Trojan Source," describes a vulnerability in the Unicode Specification (through version 14.0) that allows attackers to craft source code identifiers (like function names) using homoglyphs, making them visually identical to legitimate identifiers. This can deceive human reviewers, enabling the injection of malicious code into upstream software dependencies that is then invoked in downstream applications. While the vulnerability affects the Unicode specification itself, its impact is on applications that implement Unicode support, particularly in programming languages. This is a high-severity vulnerability with a CVSS score of 8.3. It has a network attack vector and high attack complexity, requiring user interaction (UI:R) to be successful. The potential impact is severe, leading to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no evidence of active exploitation (KEV: No), and no public exploit code is available on platforms like Metasploit or ExploitDB. However, the vulnerability has garnered significant community attention with numerous discussions and media coverage, indicating a high level of awareness and concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 14.0.0CPE matchmatch criteria | cpe:2.3:a:unicode:unicode:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.