CVE-2025-11202: win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of win-cli-mcp-server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of the resolveCommandPath method. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the service account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11202?
CVE-2025-11202 is classified as a critical vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2025-11202?
To fix CVE-2025-11202, update the win-cli-mcp-server to the latest version provided by the vendor.
Which software is affected by CVE-2025-11202?
CVE-2025-11202 affects installations of win-cli-mcp-server.
Is authentication required to exploit CVE-2025-11202?
No, authentication is not required to exploit CVE-2025-11202.
What kind of attack can be performed using CVE-2025-11202?
CVE-2025-11202 allows remote attackers to execute arbitrary code on affected installations.