PT-2021-20099 · Winscp · Winscp

Fabian Bräunlein

·

Published

2021-01-27

·

Updated

2021-02-04

·

CVE-2021-3331

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WinSCP versions prior to 5.17.10
Description The issue allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. This is exploitable in a default installation in which WinSCP is the handler for sftp:// URLs.
Recommendations For versions prior to 5.17.10, update to version 5.17.10 or later to resolve the issue. As a temporary workaround, consider restricting the use of the URL handler for sftp:// URLs until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-3331

Affected Products

Winscp