Junglewise Threat Intelligence

CVE-2026-45322: Microsoft UFO OS command injection in shell action replay

CVE-2026-45322 · Severity: high · CVSS 7.8 · Published 2026-05-27

Technologies: Microsoft UFO. Vendors: Microsoft.

Executive brief

Microsoft UFO is an open-source framework used for automating tasks across different devices and platforms. A security flaw in how the framework handles saved automation sessions allows an attacker to execute malicious commands on a user's computer. If an attacker can modify a saved session file, the malicious commands will run automatically when a user later resumes or replays that session, potentially leading to full system compromise or data theft.

Technical details

An OS command injection vulnerability exists in Microsoft UFO releases up to and including v3.0.0 within the shell action replay mechanism. The root cause is located in `ShellReceiver.run_shell()` and `ShellReceiver.execute_command()`, which pass unsanitized command strings from action parameters directly to `subprocess.Popen()` with `shell=True` and `executable=powershell.exe`. Because UFO stores planned actions in per-session JSON records, an attacker with local file system access can modify these records to include malicious payloads. When a victim resumes or replays the poisoned session, the `RunShellCommand` or `ExecuteCommand` classes forward the malicious parameters to the shell receiver, resulting in arbitrary code execution as the UFO process user. While the main branch was hardened in March 2026, no patched tagged release was available at the time of disclosure.

Affected products

  • Microsoft UFO <= v3.0.0

Timeline

  • 2026-03-25: patched: Silent hardening committed to main branch
  • 2026-05-08: advisory: GitHub security advisory published
  • 2026-05-27: disclosed: CVE published to NVD

References

Related threats