CyberRota Analysis
AI-GeneratedVersions 7.2.0 through 12.0.0 of AiSOC are vulnerable to a command injection flaw in the actions service, allowing authenticated users to exploit unescaped parameters in specific scripts. This vulnerability can lead to the execution of arbitrary commands with SYSTEM or root privileges on managed endpoints, posing a critical risk to system integrity. Organizations using affected versions should prioritize patching to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.