{"api_version":"1","generated_at":"2026-07-23T17:56:27+00:00","cve":"CVE-2021-25695","urls":{"html":"https://cve.report/CVE-2021-25695","api":"https://cve.report/api/cve/CVE-2021-25695.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-25695","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-25695"},"summary":{"title":"CVE-2021-25695","description":"The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attacker to elevate privileges by changing the flow of program execution within the vHub driver.","state":"PUBLIC","assigner":"security@teradici.com","published_at":"2021-07-21 15:15:00","updated_at":"2021-07-30 16:04:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://advisory.teradici.com/security-advisories/100/","name":"https://advisory.teradici.com/security-advisories/100/","refsource":"MISC","tags":[],"title":"Teradici Security Advisories |","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-25695","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25695","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"25695","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"teradici","cpe5":"pcoip","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-25695","ASSIGNER":"security@teradici.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"- PCoIP Agent for Windows","version":{"version_data":[{"version_value":"21.07.0"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Exposed IOCTL with Insufficient Access Control (CWE-782)"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://advisory.teradici.com/security-advisories/100/","url":"https://advisory.teradici.com/security-advisories/100/"}]},"description":{"description_data":[{"lang":"eng","value":"The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attacker to elevate privileges by changing the flow of program execution within the vHub driver."}]}},"nvd":{"publishedDate":"2021-07-21 15:15:00","lastModifiedDate":"2021-07-30 16:04:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:teradici:pcoip:*:*:*:*:*:windows:*:*","versionEndExcluding":"21.07.0","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"25695","Ordinal":"200521","Title":"CVE-2021-25695","CVE":"CVE-2021-25695","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"25695","Ordinal":"1","NoteData":"The USB vHub in the Teradici PCOIP Software Agent prior to version 21.07.0 would accept commands from any program, which may allow an attacker to elevate privileges by changing the flow of program execution within the vHub driver.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"25695","Ordinal":"2","NoteData":"2021-07-21","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"25695","Ordinal":"3","NoteData":"2021-07-21","Type":"Other","Title":"Modified"}]}}}