CVE-2021-3331

🟠 Łataj w tym tygodniu

Luka w WinSCP umożliwia zdalnym atakującym wykonanie dowolnych programów przez złośliwe URL-e.

CVSS
9.8
EPSS
7.6%
Exploit
none
Vendor
winscp
Opis źródłowy (NVD)

WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. (For example, this is exploitable in a default installation in which WinSCP is the handler for sftp:// URLs.)

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS9.8
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)7.6%
Opublikowano (NVD)2021-01-27 21:15:16 UTC
Ostatnia modyfikacja (NVD)2026-10-08 21:17:39 UTC
Referencje