Impact
UAC (Unix‑like Artifacts Collector) versions lower than 3.3.0 contain a command‑injection flaw (CWE‑78) in the _run_command function. Untrusted strings such as usernames, process names, or filenames are passed directly to the operating‑system shell, allowing an attacker to inject shell metacharacters and execute arbitrary commands. The resulting remote code execution compromises the analyst’s host, weakening confidentiality, integrity, and availability of the system.
Affected Systems
All instances of the tclahr UAC collector running any version prior to 3.3.0 are affected regardless of the underlying operating system, because the vulnerability exists in the core tool. The flaw does not depend on additional modules or extensions, so any deployment of the pre‑3.3.0 collector is at risk.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. While no EPSS score is published, the lack of an estimate does not imply low risk; it simply reflects insufficient data. The vulnerability is not listed in CISA’s KEV catalog. Attackers can provoke the flaw by supplying crafted evidence files, mounting images with hostile filenames, or tampering with artifact definitions before UAC processes them. Based on the description, it is inferred that a threat actor with access to the evidence repository or the ability to supply forensic evidence can trigger the injection; however, the description does not explicitly state the required network context, so any local or remote evidence injection that reaches the tool would exploit the flaw. Once exploited, the attacker gains unrestricted command execution on the host running UAC.
OpenCVE Enrichment