VOOZH about

URL: https://nvd.nist.gov/vuln/detail/CVE-2021-42574

⇱ NVD - CVE-2021-42574


  1. Vulnerabilities

CVE-2021-42574 Detail

Disputed     

Modified After Enrichment

This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.

Current Description

An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.


View Analysis Description

Analysis Description

** DISPUTED ** An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.

Metrics

 
NVD enrichment efforts reference publicly available information to associate vector strings. CVSS information contributed by other sources is also displayed.
CVSS 4.0 Severity and Vector Strings:

NVD assessment not yet provided.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

URL Source(s) Tag(s)
http://www.openwall.com/lists/oss-security/2021/11/01/1 CVE, MITRE Exploit  Mailing List  Mitigation  Third Party Advisory 
http://www.openwall.com/lists/oss-security/2021/11/01/4 CVE, MITRE Exploit  Mailing List  Third Party Advisory 
http://www.openwall.com/lists/oss-security/2021/11/01/5 CVE, MITRE Mailing List  Third Party Advisory 
http://www.openwall.com/lists/oss-security/2021/11/01/6 CVE, MITRE Mailing List  Third Party Advisory 
http://www.openwall.com/lists/oss-security/2021/11/02/10 CVE, MITRE Mailing List 
http://www.unicode.org/versions/Unicode14.0.0/ CVE, MITRE Release Notes  Vendor Advisory 
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/ CVE, MITRE
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/ CVE, MITRE
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/ CVE, MITRE
https://security.gentoo.org/glsa/202210-09 CVE, MITRE Third Party Advisory 
https://trojansource.codes CVE, MITRE Exploit  Technical Description  Third Party Advisory 
https://www.kb.cert.org/vuls/id/999008 CVE, MITRE Third Party Advisory  US Government Resource 
https://www.scyon.nl/post/trojans-in-your-source-code CVE, MITRE Exploit  Mitigation  Third Party Advisory 
https://www.starwindsoftware.com/security/sw-20220804-0002/ CVE, MITRE Third Party Advisory 
https://www.unicode.org/reports/tr31/ CVE, MITRE Technical Description  Vendor Advisory 
https://www.unicode.org/reports/tr36/ CVE, MITRE Technical Description  Vendor Advisory 
https://www.unicode.org/reports/tr39/ CVE, MITRE Technical Description  Vendor Advisory 
https://www.unicode.org/reports/tr9/tr9-44.html#HL4 CVE, MITRE Technical Description  Vendor Advisory 

Weakness Enumeration

CWE-ID CWE Name Source
CWE-94 Improper Control of Generation of Code ('Code Injection') πŸ‘ cwe source acceptance level
NIST  

Known Affected Software Configurations Switch to CPE 2.2

CPEs loading, please wait.

Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.

Change History

27 change records found show changes

CVE Modified by CISA-ADP 6/17/2026 12:09:50 AM

Action Type Old Value New Value
Added SSVC
{"timestamp":"2024-06-11T15:16:49.504878Z","id":"CVE-2021-42574","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}


CVE Modified by MITRE 6/17/2026 12:09:50 AM

Action Type Old Value New Value
Added Affected
[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]


CVE Modified by CVE 11/21/2024 1:27:50 AM

Action Type Old Value New Value
Added Reference
http://www.openwall.com/lists/oss-security/2021/11/01/1


Added Reference
http://www.openwall.com/lists/oss-security/2021/11/01/4


Added Reference
http://www.openwall.com/lists/oss-security/2021/11/01/5


Added Reference
http://www.openwall.com/lists/oss-security/2021/11/01/6


Added Reference
http://www.openwall.com/lists/oss-security/2021/11/02/10


Added Reference
http://www.unicode.org/versions/Unicode14.0.0/


Added Reference
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/


Added Reference
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/


Added Reference
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/


Added Reference
https://security.gentoo.org/glsa/202210-09


Added Reference
https://trojansource.codes


Added Reference
https://www.kb.cert.org/vuls/id/999008


Added Reference
https://www.scyon.nl/post/trojans-in-your-source-code


Added Reference
https://www.starwindsoftware.com/security/sw-20220804-0002/


Added Reference
https://www.unicode.org/reports/tr31/


Added Reference
https://www.unicode.org/reports/tr36/


Added Reference
https://www.unicode.org/reports/tr39/


Added Reference
https://www.unicode.org/reports/tr9/tr9-44.html#HL4


CVE Modified by MITRE 8/04/2024 12:16:04 AM

Action Type Old Value New Value

CVE Modified by MITRE 6/11/2024 12:15:15 PM

Action Type Old Value New Value

CVE Modified by MITRE 5/16/2024 10:01:34 PM

Action Type Old Value New Value

CVE Modified by MITRE 5/14/2024 5:30:41 AM

Action Type Old Value New Value

CVE Modified by MITRE 4/10/2024 9:13:06 PM

Action Type Old Value New Value

CVE Modified by MITRE 3/20/2024 10:40:42 PM

Action Type Old Value New Value
Added Tag
MITRE disputed


CVE Modified by MITRE 11/06/2023 10:39:12 PM

Action Type Old Value New Value
Changed Description
** DISPUTED ** An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.


An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.


Added Reference
MITRE https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/ [No types assigned]


Added Reference
MITRE https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/ [No types assigned]


Added Reference
MITRE https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/ [No types assigned]


Removed Reference
MITRE https://lists.fedoraproject.org/archives/list/[email protected]/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/


Removed Reference
MITRE https://lists.fedoraproject.org/archives/list/[email protected]/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/


Removed Reference
MITRE https://lists.fedoraproject.org/archives/list/[email protected]/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/


Modified Analysis by NIST 10/25/2022 12:38:28 PM

Action Type Old Value New Value
Added CPE Configuration
OR
 *cpe:2.3:a:starwindsoftware:starwind_virtual_san:v8r13:14398:*:*:*:*:*:*


Changed Reference Type
https://security.gentoo.org/glsa/202210-09 No Types Assigned


https://security.gentoo.org/glsa/202210-09 Third Party Advisory


Changed Reference Type
https://www.starwindsoftware.com/security/sw-20220804-0002/ No Types Assigned


https://www.starwindsoftware.com/security/sw-20220804-0002/ Third Party Advisory


CVE Modified by MITRE 10/16/2022 1:15:13 PM

Action Type Old Value New Value
Added Reference
https://security.gentoo.org/glsa/202210-09 [No Types Assigned]


CVE Modified by MITRE 10/11/2022 6:15:11 PM

Action Type Old Value New Value
Added Reference
https://www.starwindsoftware.com/security/sw-20220804-0002/ [No Types Assigned]


Modified Analysis by NIST 9/02/2022 11:59:28 PM

Action Type Old Value New Value
Changed Reference Type
https://www.unicode.org/reports/tr31/ No Types Assigned


https://www.unicode.org/reports/tr31/ Technical Description, Vendor Advisory


Changed Reference Type
https://www.unicode.org/reports/tr36/ No Types Assigned


https://www.unicode.org/reports/tr36/ Technical Description, Vendor Advisory


Changed Reference Type
https://www.unicode.org/reports/tr39/ No Types Assigned


https://www.unicode.org/reports/tr39/ Technical Description, Vendor Advisory


Changed Reference Type
https://www.unicode.org/reports/tr9/tr9-44.html#HL4 No Types Assigned


https://www.unicode.org/reports/tr9/tr9-44.html#HL4 Technical Description, Vendor Advisory


CVE Modified by MITRE 5/12/2022 11:15:07 AM

Action Type Old Value New Value
Changed Description
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers.


** DISPUTED ** An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic than the logical ordering of tokens ingested by compilers and interpreters. Adversaries can leverage this to encode source code for compilers accepting Unicode such that targeted vulnerabilities are introduced invisibly to human reviewers. NOTE: the Unicode Consortium offers the following alternative approach to presenting this concern. An issue is noted in the nature of international text that can affect applications that implement support for The Unicode Standard and the Unicode Bidirectional Algorithm (all versions). Due to text display behavior when text includes left-to-right and right-to-left characters, the visual order of tokens may be different from their logical order. Additionally, control characters needed to fully support the requirements of bidirectional text can further obfuscate the logical order of tokens. Unless mitigated, an adversary could craft source code such that the ordering of tokens perceived by human reviewers does not match what will be processed by a compiler/interpreter/etc. The Unicode Consortium has documented this class of vulnerability in its document, Unicode Technical Report #36, Unicode Security Considerations. The Unicode Consortium also provides guidance on mitigations for this class of issues in Unicode Technical Standard #39, Unicode Security Mechanisms, and in Unicode Standard Annex #31, Unicode Identifier and Pattern Syntax. Also, the BIDI specification allows applications to tailor the implementation in ways that can mitigate misleading visual reordering in program text; see HL4 in Unicode Standard Annex #9, Unicode Bidirectional Algorithm.


Added Reference
https://www.unicode.org/reports/tr31/ [No Types Assigned]


Added Reference
https://www.unicode.org/reports/tr36/ [No Types Assigned]


Added Reference
https://www.unicode.org/reports/tr39/ [No Types Assigned]


Added Reference
https://www.unicode.org/reports/tr9/tr9-44.html#HL4 [No Types Assigned]


Modified Analysis by NIST 11/30/2021 3:22:29 PM

Action Type Old Value New Value
Changed Reference Type
https://www.scyon.nl/post/trojans-in-your-source-code No Types Assigned


https://www.scyon.nl/post/trojans-in-your-source-code Exploit, Mitigation, Third Party Advisory


CVE Modified by MITRE 11/26/2021 9:15:07 AM

Action Type Old Value New Value
Added Reference
https://www.scyon.nl/post/trojans-in-your-source-code [No Types Assigned]


Modified Analysis by NIST 11/16/2021 10:16:57 AM

Action Type Old Value New Value
Added CVSS V3.1
NIST AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H


Removed CVSS V3.1
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Added CVSS V2
NIST (AV:N/AC:H/Au:N/C:P/I:P/A:P)


Removed CVSS V2
NIST (AV:N/AC:L/Au:N/C:P/I:P/A:P)


Added CPE Configuration
OR
 *cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
 *cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
 *cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*


Changed Reference Type
http://www.openwall.com/lists/oss-security/2021/11/02/10 No Types Assigned


http://www.openwall.com/lists/oss-security/2021/11/02/10 Mailing List


Changed Reference Type
https://lists.fedoraproject.org/archives/list/[email protected]/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/ No Types Assigned


https://lists.fedoraproject.org/archives/list/[email protected]/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/ Mailing List, Third Party Advisory


Changed Reference Type
https://lists.fedoraproject.org/archives/list/[email protected]/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/ No Types Assigned


https://lists.fedoraproject.org/archives/list/[email protected]/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/ Mailing List, Third Party Advisory


Changed Reference Type
https://lists.fedoraproject.org/archives/list/[email protected]/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/ No Types Assigned


https://lists.fedoraproject.org/archives/list/[email protected]/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/ Mailing List, Third Party Advisory


Changed Reference Type
https://www.kb.cert.org/vuls/id/999008 No Types Assigned


https://www.kb.cert.org/vuls/id/999008 Third Party Advisory, US Government Resource


Added CVSS V2 Metadata
Victim must voluntarily interact with attack mechanism


CVE Modified by MITRE 11/10/2021 10:15:07 PM

Action Type Old Value New Value
Added Reference
https://lists.fedoraproject.org/archives/list/[email protected]/message/IH2RG5YTR6ZZOLUV3EUPZEIJR7XHJLVD/ [No Types Assigned]


CVE Modified by MITRE 11/09/2021 1:15:07 PM

Action Type Old Value New Value
Added Reference
https://www.kb.cert.org/vuls/id/999008 [No Types Assigned]


CVE Modified by MITRE 11/05/2021 12:15:16 AM

Action Type Old Value New Value
Added Reference
https://lists.fedoraproject.org/archives/list/[email protected]/message/LQNTFF24ROHLVPLUOEISBN3F7QM27L4U/ [No Types Assigned]


CVE Modified by MITRE 11/04/2021 12:15:12 AM

Action Type Old Value New Value
Added Reference
https://lists.fedoraproject.org/archives/list/[email protected]/message/QUPA37D57VPTDLSXOOGF4UXUEADOC4PQ/ [No Types Assigned]


CVE Modified by MITRE 11/02/2021 8:15:08 PM

Action Type Old Value New Value
Added Reference
http://www.openwall.com/lists/oss-security/2021/11/02/10 [No Types Assigned]


Initial Analysis by NIST 11/02/2021 2:43:39 PM

Action Type Old Value New Value
Added CVSS V3.1
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Added CVSS V2
NIST (AV:N/AC:L/Au:N/C:P/I:P/A:P)


Added CWE
NIST CWE-94


Added CPE Configuration
OR
 *cpe:2.3:a:unicode:unicode:*:*:*:*:*:*:*:* versions up to (excluding) 14.0.0


Changed Reference Type
http://www.openwall.com/lists/oss-security/2021/11/01/1 No Types Assigned


http://www.openwall.com/lists/oss-security/2021/11/01/1 Exploit, Mailing List, Mitigation, Third Party Advisory


Changed Reference Type
http://www.openwall.com/lists/oss-security/2021/11/01/4 No Types Assigned


http://www.openwall.com/lists/oss-security/2021/11/01/4 Exploit, Mailing List, Third Party Advisory


Changed Reference Type
http://www.openwall.com/lists/oss-security/2021/11/01/5 No Types Assigned


http://www.openwall.com/lists/oss-security/2021/11/01/5 Mailing List, Third Party Advisory


Changed Reference Type
http://www.openwall.com/lists/oss-security/2021/11/01/6 No Types Assigned


http://www.openwall.com/lists/oss-security/2021/11/01/6 Mailing List, Third Party Advisory


Changed Reference Type
http://www.unicode.org/versions/Unicode14.0.0/ No Types Assigned


http://www.unicode.org/versions/Unicode14.0.0/ Release Notes, Vendor Advisory


Changed Reference Type
https://trojansource.codes No Types Assigned


https://trojansource.codes Exploit, Technical Description, Third Party Advisory


CVE Modified by MITRE 11/01/2021 5:15:08 PM

Action Type Old Value New Value
Added Reference
http://www.openwall.com/lists/oss-security/2021/11/01/5 [No Types Assigned]


Added Reference
http://www.openwall.com/lists/oss-security/2021/11/01/6 [No Types Assigned]


CVE Modified by MITRE 11/01/2021 2:15:08 PM

Action Type Old Value New Value
Added Reference
http://www.openwall.com/lists/oss-security/2021/11/01/4 [No Types Assigned]


CVE Modified by MITRE 11/01/2021 5:15:09 AM

Action Type Old Value New Value
Added Reference
http://www.openwall.com/lists/oss-security/2021/11/01/1 [No Types Assigned]


Quick Info

CVE Dictionary Entry:
CVE-2021-42574
NVD Published Date:
11/01/2021
NVD Last Modified:
06/17/2026
Source:
MITRE