Microsoft UFO 是一个跨设备和平台的开源智能自动化框架。在 3.0.9 版本之前,位于 中的 工具将 和 视为只读命令。然而,由于支持自由格式的命令行参数,这些命令的文件输出形式仍可被调用。 经过身份验证的用户可以利用 或 的可选第二个操作数,在不使用 shell 元字符的情况下,创建或覆盖 UFO 服务器进程具有写入权限的文件。这是因为受允许的指令会自行打开目标文件,而当前的参数策略并未拒绝此类操作。该漏洞可能导致配置文件或其他可写数据损坏,并破坏服务正常运行。但所演示的攻击原语不会直接泄露文件,也无
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105794 | 9.1 CRITICAL | MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL |
| CVE-2026-105793 | 9.1 CRITICAL | Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key` |
| CVE-2026-105797 | 8.8 HIGH | SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spaw |
| CVE-2026-105796 | 8.8 HIGH | Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP gene |
| CVE-2026-105788 | 8.8 HIGH | Microsoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and l |
| CVE-2026-105798 | 8.7 HIGH | SimpleChat: Stored XSS via group document filename in inline onclick handler |
| CVE-2026-105791 | 7.5 HIGH | Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` argument injecti |
| CVE-2026-105792 | 6.5 MEDIUM | Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager |
| CVE-2026-105790 | 6.4 MEDIUM | Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinni |
| CVE-2026-105795 | 3.1 LOW | Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests |
No comments yet