← Back to browse · API

CVE-2021-41193

Severity
CRITICAL
CVSS
9.8
EPSS
0.02466
Risk score
40.06
CISA KEV
No
PoC
No
Published
2022-03-01
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2022-1271, GHSA-2J6V-XPF3-XVRV
Products
wireapp:wire-avs < 7.1.12
Sources
euvd EUVD-2022-1271

Description

wire-avs is the audio visual signaling (AVS) component of Wire, an open-source messenger. A remote format string vulnerability in versions prior to 7.1.12 allows an attacker to cause a denial of service or possibly execute arbitrary code. The issue has been fixed in wire-avs 7.1.12. There are currently no known workarounds.

References