
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2021-3331 is a security vulnerability discovered in WinSCP versions before 5.17.10, disclosed in January 2021. The vulnerability allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted URL that loads session settings. This is particularly exploitable in default installations where WinSCP is configured as the handler for sftp:// URLs (NVD, CVE).
The vulnerability stems from improper validation of user-supplied input data in the URL handler functionality of WinSCP. When processing URLs that load session settings, the application fails to properly validate the input, allowing attackers to execute arbitrary programs. The issue was particularly concerning as it affected default installations where WinSCP was configured to handle sftp:// URLs (NVD).
The vulnerability enables remote attackers to execute arbitrary programs on the target system through crafted URLs, potentially leading to complete system compromise. This is particularly significant as it affects default installations of WinSCP where it handles sftp:// URLs, making it a widespread potential attack vector (NVD, Hacker News).
The vulnerability is exploitable when an attacker can convince a user to interact with a specially crafted URL that loads session settings. The attack vector is particularly effective in default installations where WinSCP is registered as the handler for sftp:// URLs (NVD).
The vulnerability was addressed in WinSCP version 5.17.10. Users are advised to upgrade to this version or later to protect against this security issue. The fix prevents loading session settings that could lead to remote code execution from handled URLs (WinSCP History, WinSCP Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."