Impact
AiSOC versions 7.2.0 through before 12.0.0 contain a command injection flaw in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters. Authenticated users can inject single quotes into the file_path, path, script_name, or script_args parameters to break out of the quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges. The vulnerability enables an attacker to run any command on the target machines, leading to full system compromise.
Affected Systems
The affected product is AiSOC, released by beenuar. All instances of AiSOC version 7.2.0 up to but not including 12.0.0 are impacted, as the vulnerability resides in the actions service of those releases.
Risk and Exploitability
The CVSS score is 9.4, indicating critical severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. The attack requires authenticated access to the AiSOC actions service; an attacker with valid credentials can supply malicious parameters and trigger command execution on endpoints. Given the high severity, the likelihood of exploitation is significant if the defect persists in an environment that permits such authenticated operations.
OpenCVE Enrichment