CyberRota Analysis
AI-GeneratedThe Microsoft UFO framework prior to version 3.0.8 is vulnerable due to exposed Streamable HTTP MCP services on TCP ports 8020 and 8021, which lack authentication. This allows unauthenticated remote attackers to execute various commands on ADB-connected Android devices, potentially disclosing sensitive screen and device data and altering device states. Organizations utilizing this framework, particularly those managing Android devices, should prioritize upgrading to version 3.0.8 to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports 8020 and 8021 without authentication, allowing an unauthenticated remote attacker to invoke capture_screenshot, get_ui_tree, tap, swipe, type_text, launch_app, press_key, and click_control against an ADB-connected Android device, disclose screen and device data, and modify device state. This issue is fixed in version 3.0.8.