Impact
The vulnerability resides in SiYuan versions earlier than 3.7.4, where the application does not escape workspace directory paths when building command-line arguments for the elevated elevator.exe helper. An attacker can create a workspace folder whose name includes command metacharacters, causing the helper to execute those commands with administrator privileges after a User‑Account‑Control prompt. This results in arbitrary code execution on the local machine with elevated rights.
Affected Systems
Siyuan Note’s SiYuan desktop application versions prior to 3.7.4. The vulnerability applies to all installations that use the default elevator.exe helper and Microsoft Defender exclusion flow in Windows environments.
Risk and Exploitability
With a CVSS score of 8.6 the vulnerability is considered high severity. The EPSS score is not available, but the lack of a near‑term public exploit and absence from the KEV catalog suggest a lower, though still significant, exploitation probability. Since the flaw is triggered by a local attacker creating a specially crafted directory, it requires local access and acceptance of the UAC prompt. Once the prompt is accepted, the attacker regains system‑level command execution through the vulnerable helper. The attack path hinges on the interaction between the escaped path, Microsoft Defender’s exclusion mechanism, and the elevation process.
OpenCVE Enrichment