MsQuic 是一个跨平台的 C 语言实现,提供了对 IETF QUIC 协议的支持,并暴露给 C、C++、C和 Rust 编程语言。在版本 2.4.20、2.5.11 和 2.6.1 之前,使用 OpenSSL 或 QuicTLS TLS 后端的 MsQuic 客户端未能正确验证服务器证书是否与预期的目标服务器主机名匹配。因此,中间人攻击者可以展示一个不匹配预期目标主机名的证书,从而在中间人攻击中伪造服务器身份。Schannel 后端不受此问题影响。该问题已在版本 2.4.20、2.5.11 和 2.6.1 中修
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105793 | 9.1 CRITICAL | Microsoft UFO: Authenticated Android shell command injection in Mobile MCP `press_key` |
| CVE-2026-105797 | 8.8 HIGH | SimpleChat: Command injection via authorization-gate ordering flaw (arbitrary process spaw |
| CVE-2026-105796 | 8.8 HIGH | Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP gene |
| CVE-2026-105788 | 8.8 HIGH | Microsoft UFO: Authenticated Android shell command injection in Mobile MCP type_text and l |
| CVE-2026-105798 | 8.7 HIGH | SimpleChat: Stored XSS via group document filename in inline onclick handler |
| CVE-2026-105791 | 7.5 HIGH | Microsoft UFO: Arbitrary code execution in `run_shell` via `explorer.exe` argument injecti |
| CVE-2026-105792 | 6.5 MEDIUM | Microsoft UFO: Authenticated task-result request can deadlock UFO server session manager |
| CVE-2026-105790 | 6.4 MEDIUM | Microsoft UFO: Authenticated Galaxy device registration can bypass WebSocket SSRF IP pinni |
| CVE-2026-105789 | 5.4 MEDIUM | Microsoft UFO: Arbitrary file write in the Linux MCP `execute_command` tool |
| CVE-2026-105795 | 3.1 LOW | Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests |
No comments yet