VDB
Sign up
—

PYSEC-2021-112

Quick fix

PYSEC-2021-112 — pywin32: upgrade to the fixed version with the command below.

pip install --upgrade 'pywin32>=301'

Details

An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/pywin32
Introduced in: 0Fixed in: 301
Fixpip install --upgrade 'pywin32>=301'

References