Impact
Microsoft UFO’s press_key tool accepts an unvalidated key_code argument and forwards it to the adb shell. An attacker who authenticates with a valid UFO_MCP_API_KEY can inject additional commands, causing the Android shell user to execute arbitrary commands on a connected device. The flaw does not elevate privileges beyond the Android shell user or grant host‑OS access, but it still allows privileged operations on the device. The weakness is a classic shell injection (CWE‑78).
Affected Systems
Microsoft UFO is affected in all releases prior to version 3.0.9. Anyone using an older UFO build and exposing the Mobile MCP press_key endpoint, with an active UFO_MCP_API_KEY, could be impacted. The vulnerability is fixed in UFO v3.0.9 and later.
Risk and Exploitability
With a CVSS score of 9.1, this flaw poses a high risk. EPSS is not available, and it is not listed in the CISA KEV catalog. Exploitation requires that the attacker have a valid UFO_MCP_API_KEY, that the UFO host has adb installed, that a device is connected and reachable, and that the press_key endpoint is exposed. Once those conditions are met, the attacker can run commands as the Android shell user. The attack surface is therefore limited to devices configured for the UFO Mobile MCP API, but the impact on each device is significant, allowing control over installed applications, data, and device state.
OpenCVE Enrichment