Impact
The vulnerability is an OS command injection in the vsDesk Task Scheduler caused by insufficient input filtering. An authenticated attacker with administrative privileges can supply arbitrary command strings that are executed by the underlying operating system. This flaw permits execution of any OS command, allowing an attacker to disrupt web server functions, expose sensitive data, or ultimately gain full server compromise. The weakness corresponds to CWE‑676, an incomplete validation of inputs prior to OS command execution.
Affected Systems
Affected systems are deployments of the vsDesk application before version 14.0101. Any installation running a pre‑14.0101 build is vulnerable and the flaw applies to the Task Scheduler component of vsDesk, requiring the user to be logged in with administrative rights.
Risk and Exploitability
The CVSS score of 8.6 categorises the issue as high severity. The EPSS score of less than 1 % indicates a low probability of exploitation at this point, and the flaw is not listed in the CISA KEV catalog. Nevertheless, because the vulnerability demands administrative access, an internal attacker or a compromised admin account can exploit it. The attacker would create or modify a scheduler task with a crafted command line, which is then executed with the privileges of the web application.
OpenCVE Enrichment