Impact
The vulnerability originates from patool's shell_quote_nt function failing to escape cmd.exe metacharacters or embedded double quotes in archive filenames. This flaw allows attackers to supply crafted filenames such as report&calc.gz and cause patool to run them as shell commands under the patool process via shell=True. If exploited, an attacker can execute arbitrary commands with the privileges of the user running patool, leading to full system compromise.
Affected Systems
Patool, released by wummel, is vulnerable on all versions earlier than 4.0.6 when executed on Windows. Any Windows system that uses an older patool package to extract archives that contain specially crafted filenames is at risk. The problem resides exclusively in the Windows environment and does not affect other operating systems.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. Because the EPSS score is not available, the exact likelihood of exploitation remains unknown, but the vulnerability is listed in no KEV catalogue, implying no known widespread exploitation. The attack vector is local as an attacker must supply a malicious archive; however, if an attacker can write to a shared location or upload a file to a service that invokes patool, the risk grows. Exploitation requires use of shell=True by patool, which is the default for many formats, making mitigations straightforward by upgrading.
OpenCVE Enrichment