A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-18713 | A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 24 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'. | A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'. |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-08-03T23:10:30.172Z
Reserved: 2021-04-27T00:00:00.000Z
Link: CVE-2021-31838
No data.
Status : Modified
Published: 2021-06-29T10:15:08.543
Modified: 2026-02-24T17:27:22.603
Link: CVE-2021-31838
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD