890
VMScore

CVE-2021-44041

Published: 14/12/2021 Updated: 20/12/2021
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an malicious user to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

uipath assistant 21.4.4