Home
CRITICAL: 9.4 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDefault status
unaffected
Any version before 2024.MS4.33
affected
Description
The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on the system.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before 2024.MS4.33
Credits
Maciej Kazulak
References
cert.pl/en/posts/2025/08/CVE-2025-2313/