PT-2026-50529 · Hackplayers · Evil-Winrm
Tristan Madani
·
Published
2026-06-17
·
Updated
2026-06-17
·
CVE-2026-55201
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N |
Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download dir() function that allows a rogue or compromised remote Windows server to write files outside the intended download directory by returning filenames with traversal sequences from Get-ChildItem command output that are passed unsanitized to File.join(). Attackers controlling the remote server can exploit this to overwrite sensitive client-side files such as SSH authorized keys or shell configuration files, achieving persistent access or privilege escalation on the client machine.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evil-Winrm