Sceawere
Vulnerability Detail
CVE-2026-105789UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft UFO Arbitrary File Write
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 11h ago
- Vendor
- microsoft
- Product
- UFO
- Attack Type
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the execute_command tool in ufo/client/mcp/http_servers/linux_mcp_server.py treats sort and uniq as read-only commands while the free-form command parameter can select their file-output forms. An authenticated caller can use sort -o or the optional second uniq operand to create or overwrite files writable by the UFO server process without shell metacharacters, because the allowed binary opens the destination itself and the argument policy does not reject the operation. This can corrupt configuration or other writable data and disrupt the service, but the demonstrated primitive does not directly disclose files or establish arbitrary code execution. This issue is fixed in version 3.0.9.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-06T14:17:40.270Z",
"pubdate": "2026-10-06T14:17:40.270Z",
"executiveSummary": "The Microsoft UFO framework, prior to version 3.0.9, contains an arbitrary file write vulnerability within the execute_command tool located in ufo/client/mcp/http_servers/linux_mcp_server.py.\nThe vulnerability arises from improper input validation when handling the 'sort' and 'uniq' system utilities. Although the application attempts to restrict commands to read-only operations, it fails to account for the file-output parameters supported by these specific binaries.\nAn authenticated attacker can leverage the 'sort -o' flag or the secondary operand of the 'uniq' utility to overwrite or create files within the filesystem that are writable by the UFO server process.\nWhile this primitive does not inherently grant arbitrary code execution or direct file disclosure, it enables an attacker to corrupt critical configuration files or application data, potentially leading to a service disruption or denial of service.\nSuccessful exploitation requires the attacker to be authenticated to the UFO service. The lack of validation on command arguments allows the execution of unintended file-writing operations despite the intended read-only nature of the tool.",
"technicalDetails": "The root cause of this vulnerability is an inadequate argument policy enforcement within the execute_command function in the file ufo/client/mcp/http_servers/linux_mcp_server.py. The application employs a restricted whitelist of commands, specifically 'sort' and 'uniq', under the assumption that these utilities are strictly read-only when executed without specific flags.\nHowever, the implementation fails to inspect the free-form command parameter for arguments that trigger file write operations. Specifically, the 'sort' command supports the '-o' (output) flag, which directs the results of the sorting operation to a user-specified file. Similarly, the 'uniq' command supports a secondary operand that defines an output file for filtered results. Because these binaries themselves handle the file opening process, they bypass standard shell metacharacter filters, as the operation does not require shell redirection operators such as '>' or '>>'.\nThe attack flow proceeds as follows: An authenticated user interacts with the execute_command interface provided by the linux_mcp_server.py component. The user submits a command string incorporating either 'sort -o [path_to_target_file]' or 'uniq [input_file] [path_to_target_file]'. The application validates that the primary command is in the whitelist and passes the arguments to the system process execution handler. Because the argument policy does not sanitize or explicitly forbid the output-related flags and operands, the underlying OS executes the binary with the user-supplied file path as the destination.\nThe UFO server process acts as the initiator, meaning the target file must have permissions that allow the server process to write to it. If the server is running with elevated privileges or has broad write access to application configuration files or persistent data structures, an attacker can overwrite these files with the output of the 'sort' or 'uniq' operations. This leads to configuration corruption or data loss. The vulnerability is present in all versions of Microsoft UFO prior to 3.0.9. Mitigation requires upgrading to 3.0.9, which presumably addresses the logic error by strengthening argument validation to explicitly prohibit flags and operands that facilitate file creation or modification."
}