CVE-2021-44041: Critical severity uipath vulnerability
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44041?
CVE-2021-44041 is considered to be a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2021-44041?
To fix CVE-2021-44041, update UiPath Assistant to the latest version beyond 21.4.4 that addresses this vulnerability.
Which versions of UiPath Assistant are affected by CVE-2021-44041?
CVE-2021-44041 specifically affects UiPath Assistant version 21.4.4.
What type of attack is possible through CVE-2021-44041?
CVE-2021-44041 allows an attacker to execute arbitrary code or capture NTLM credentials.
Is there a way to mitigate the risks associated with CVE-2021-44041?
A potential mitigation for CVE-2021-44041 is to avoid using the --dev-widget argument unless absolutely necessary.