Impact
An issue in Milos Paripovic OneCommander version 3.96.0.0 enables a remote attacker to trigger arbitrary code execution by manipulating the OneCommander.exe component. This flaw allows the attacker to run any commands on the affected system, potentially compromising confidentiality, integrity, and availability of the host. The weakness is a remote code execution vulnerability, indicating that the attacker can execute code without local interaction or privileged access.
Affected Systems
The affected product is Milos Paripovic OneCommander 3.96.0.0, specifically its OneCommander.exe component. No other vendors, products, or version details are listed.
Risk and Exploitability
The CVSS score of 8.8 indicates severe risk, while the EPSS score of 0.00363 denotes a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog and no public exploits are currently known. Nevertheless, because the flaw permits arbitrary code execution through the OneCommander.exe component, any attacker who can reach the OneCommander service over the network could potentially compromise confidentiality, integrity, and availability of the target system.
OpenCVE Enrichment