Impact
Microsoft Power Automate Desktop contains a relative path traversal flaw that allows a user with authorized application access to craft file names that reference arbitrary system directories. By manipulating file paths, an attacker can write or overwrite files outside the intended working directory, leading to local privilege escalation. The vulnerability is classified under CWE-23 and can compromise the confidentiality, integrity, or availability of the system on which Power Automate is installed.
Affected Systems
The flaw affects Microsoft Power Automate agent for virtual desktops and Microsoft Power Automate for Desktop. No specific version ranges are mentioned, so all installed instances are potentially vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score is 7, reflecting a medium to high severity. EPSS score is not available but the lack of public exploit data suggests a low to moderate likelihood of widespread exploitation. The vulnerability is not listed in CISA KEV. The attack vector is local and requires that the attacker has interactive or script-based access to the Power Automate process, so only users with authorized access to the application can exploit this flaw.
OpenCVE Enrichment