PT-2026-50529 · Unknown · Evil-Winrm
CVSS v4.0
7.4
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Evil-WinRM versions prior to commit 6ecd570
Description
A path traversal issue exists in the
download dir() function. This occurs when the software fails to sanitize filenames returned from the Get-ChildItem command output before passing them to File.join(). A compromised or rogue remote Windows server can return filenames containing traversal sequences, enabling the server to write files outside the intended download directory on the client machine. This can be used to overwrite sensitive files, such as SSH authorized keys or shell configuration files, potentially leading to privilege escalation or persistent access on the client system.Recommendations
Update to the version containing commit 6ecd570.
As a temporary workaround, restrict the use of the
download dir() function when connecting to untrusted remote servers.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Evil-Winrm