Sceawere
Vulnerability Detail
CVE-2026-105791UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft UFO Arbitrary Command Execution
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 10h ago
- Vendor
- microsoft
- Product
- UFO
- Attack Type
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Microsoft UFO is an open-source framework for intelligent automation across devices and platforms. Prior to 3.0.9, the run_shell tool in the CommandLineExecutor component of ufo/client/mcp/local_servers/cli_mcp_server.py validates only the first token of the bash_command parameter and permits explorer.exe. On Windows, explorer.exe delegates its following path argument to ShellExecute, so an attacker-influenced agent call can launch an arbitrary executable or script as the desktop user even though the subprocess uses shell=False. Exploitation depends on a user running an affected agent workflow and on inducing the tool call, but successful execution can access or modify that user's files, tokens, and sessions. This issue is fixed in version 3.0.9.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-06T15:17:15.840Z",
"pubdate": "2026-10-06T15:17:15.840Z",
"executiveSummary": "The Microsoft UFO framework, prior to version 3.0.9, contains a critical security vulnerability within the CommandLineExecutor component. The vulnerability is classified as an improper input validation flaw that leads to arbitrary command execution.\nThe issue stems from insufficient sanitization of the bash_command parameter in the run_shell tool, located in ufo/client/mcp/local_servers/cli_mcp_server.py. By leveraging the specific behavior of explorer.exe on Windows, an attacker-influenced agent call can bypass intended execution restrictions.\nThis allows a malicious actor to execute arbitrary binaries or scripts under the context of the user running the affected agent workflow. The impact is significant, as successful exploitation provides the attacker with the ability to modify, delete, or exfiltrate user files, intercept session tokens, and compromise local user data.\nExploitation requires an attacker to successfully induce a tool call within a user-executed agent workflow. Because the process is launched by the desktop user, the attacker inherits the full permissions of that user, posing a severe risk to system integrity and data confidentiality.",
"technicalDetails": "The vulnerability resides in the run_shell tool within the ufo/client/mcp/local_servers/cli_mcp_server.py file. The core root cause is an incomplete allowlist validation mechanism that only inspects the first token of the provided bash_command parameter.\nIn the affected versions (prior to 3.0.9), the implementation permits the execution of explorer.exe. On Windows systems, when explorer.exe receives path arguments, it internally delegates the processing to the ShellExecute API. Even though the Python subprocess call is configured with shell=False, the secondary delegation to ShellExecute interprets subsequent arguments as commands or paths to be executed.\nThis creates an effective bypass of the security boundary, as the initial validation only checks the primary executable and fails to sanitize the trailing arguments. An attacker can craft a payload by providing explorer.exe as the primary command followed by a malicious executable or script path as an argument.\nThe attack flow follows these steps: 1. An attacker influences an agent workflow to trigger a call to the run_shell tool. 2. The malicious command is structured as 'explorer.exe [malicious_binary_path]'. 3. The CommandLineExecutor validates 'explorer.exe' as a permitted command. 4. The subprocess is invoked with shell=False, but the arguments are passed to the underlying OS. 5. Windows ShellExecute interprets the path argument to explorer.exe and launches the target binary.\nBecause the agent workflow is executed by the desktop user, the payload runs with that user's full privileges. This allows for post-exploitation activities such as unauthorized access to the user's sensitive files, manipulation of active session tokens, and potential persistence mechanisms within the user profile. There is no requirement for network-level exposure or special authentication, as the execution occurs entirely within the local context of the agent session."
}