Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7h9v-7266-h9v7

Опубликовано: 15 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

EPSS

Процентиль: 74%
0.00829
Низкий

Дефекты

CWE-610

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

EPSS

Процентиль: 74%
0.00829
Низкий

Дефекты

CWE-610