Vulnerability Description
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Uipath | Assistant | 21.4.4 |
Related Weaknesses (CWE)
References
- https://docs.uipath.com/robot/docs/release-notes-2021-10-4Release NotesVendor Advisory
- https://docs.uipath.com/robot/docs/uipath-assistantProduct
- https://docs.uipath.com/robot/docs/release-notes-2021-10-4Release NotesVendor Advisory
- https://docs.uipath.com/robot/docs/uipath-assistantProduct
FAQ
What is CVE-2021-44041?
CVE-2021-44041 is a vulnerability with a CVSS score of 9.8 (CRITICAL). UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to e...
How severe is CVE-2021-44041?
CVE-2021-44041 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-44041?
Check the references section above for vendor advisories and patch information. Affected products include: Uipath Assistant.