PT-2026-102966 · Crowdstrike+1 · Crowdstrike Real Time Response+1
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
AiSOC versions 7.2.0 through 11.x
Description
The actions service contains a flaw when building CrowdStrike Real Time Response command strings by interpolating unescaped action parameters within
crowdstrike rtr.py and endpoint.py. Authenticated users can inject single quotes into the file path, path, script name, or script args parameters to bypass quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.Recommendations
Update AiSOC to version 12.0.0 or later.
Restrict the use of the
file path, path, script name, and script args parameters until the update is applied.Exploit
Fix
LPE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aisoc
Crowdstrike Real Time Response