CVE-2021-41352 is an information disclosure vulnerability affecting Microsoft System Center Operations Manager (SCOM). With a CVSS score of 7.5 (High), it can be exploited remotely without authentication and with low attack complexity, potentially leading to significant data exposure. While there is no known public exploit code or active exploitation (not in KEV), its EPSS and FAUCET scores indicate a moderate risk, and it received limited community and media attention during the October 2021 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2012CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2012:r2:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2016:-:*:*:*:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:microsoft:system_center_operations_manager:2019:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.