CVE-2026-105791: falha de alta gravidade em microsoft UFO
Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` argument injection
Publicada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.5epss 0.6%
probabilidade de exploração
0.6%top 52% das CVEs
exploração observada
nãonenhuma fonte reporta
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attacker-influenced agent call can launch an arbitrary executable or script as the desktop user even though the subprocess uses shell=False. Exploitation depends on a user running an affected agent workflow and on inducing the tool call, but successful execution can access or modify that user's files, tokens, and sessions. This issue is fixed in version 3.0.9.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Produtos afetados
microsoft · UFOCVEs relacionadas — microsoft UFO
No mesmo produto, das mais perigosas para as menos.
CVE-2026-73296CRITICALMicrosoft UFO: Unauthenticated Mobile MCP access allows remote Android device control and screen disclosureEPSS 3.7%CVE-2026-73297MEDIUMMicrosoft UFO: IPv6 transition address bypass of SSRF guard in URL validationEPSS 2.9%CVE-2026-45322HIGHOS Command Injection in Microsoft UFO Shell Action Replay via Stored Session JSONEPSS 2.1%CVE-2026-55440MEDIUMMicrosoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of serviceEPSS 1.3%CVE-2026-105788HIGHMicrosoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and launch_appEPSS 1.1%CVE-2026-46402HIGHMicrosoft UFO uses untrusted task_name in log paths, allowing authenticated path traversal and log file creation outside the logs directoryEPSS 1.0%