CVE-2021-3331
WinSCP vulnerability analysis and mitigation

Overview

CVE-2021-3331 is a security vulnerability discovered in WinSCP versions before 5.17.10, disclosed in January 2021. The vulnerability allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. This is particularly exploitable in default installations where WinSCP is configured as the handler for sftp:// URLs (NVD, CVE).

Technical details

The vulnerability stems from improper validation of user-supplied input data in the URL handler functionality of WinSCP. When processing URLs that load session settings, the application fails to properly validate the input, allowing attackers to execute arbitrary programs. The issue was particularly concerning as it affected default installations where WinSCP was configured to handle sftp:// URLs (NVD).

Impact

The vulnerability enables remote attackers to execute arbitrary programs on the target system through crafted URLs, potentially leading to complete system compromise. This is particularly significant as it affects default installations of WinSCP where it handles sftp:// URLs, making it a widespread potential attack vector (NVD, Hacker News).

Exploitability

The vulnerability is exploitable when an attacker can convince a user to interact with a specially crafted URL that loads session settings. The attack vector is particularly effective in default installations where WinSCP is registered as the handler for sftp:// URLs (NVD).

Mitigation and workarounds

The vulnerability was addressed in WinSCP version 5.17.10. Users are advised to upgrade to this version or later to protect against this security issue. The fix prevents loading session settings that could lead to remote code execution from handled URLs (WinSCP History, WinSCP Tracker).

Additional resources


SourceThis report was generated using AI

Related WinSCP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-3331CRITICAL9.8
  • WinSCP logoWinSCP
  • cpe:2.3:a:winscp:winscp
NoYesJan 27, 2021
CVE-2020-28864CRITICAL9.8
  • WinSCP logoWinSCP
  • cpe:2.3:a:winscp:winscp
NoYesNov 23, 2020
CVE-2024-31497MEDIUM5.9
  • NixOS logoNixOS
  • filezilla-debugsource
NoYesApr 15, 2024
CVE-2023-48795MEDIUM5.9
  • MySQL logoMySQL
  • external-dns
NoYesDec 18, 2023
CVE-2019-6111MEDIUM5.9
  • NixOS logoNixOS
  • openssh-ldap
NoYesJan 31, 2019

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management