Impact
The BOSH CLI tool on Windows contains a command injection flaw that allows attackers to execute arbitrary PowerShell commands. Inferred from the nature of the vulnerability, an attacker could run any commands with the privileges of the user running the CLI, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The issue impacts the BOSH CLI distributed by the Cloud Foundry Foundation for Windows platforms. No specific version information is provided, so all unpatched Windows builds of the CLI may be vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity. EPSS data shows a 2% likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, since the CLI is often invoked by processes that can supply command arguments. Successful exploitation would grant the attacker full execution rights on the host running the CLI.
OpenCVE Enrichment