#VU107572 Uncontrolled search path element in Power Automate for Desktop - CVE-2025-29817
Published: April 17, 2025
Power Automate for Desktop
Microsoft
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to the application loads its components in an insecure manner. A remote attacker can trick the victim into opening a specially crafted file that references an application component on a remote SMB share and obtain victim's NTLM hash.