OS Command Injection in Windows and Windows Server - #VU50137
Published: January 29, 2021
Windows
Windows Server
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the shell handler for opening a folder in PowerShell. Crafted data in a folder name can trigger execution of a system call composed from a user-supplied string. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary commands on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.