CVE-2026-103056 AiSOC actions 服务命令注入漏洞
影响攻击者可在受管端点以 SYSTEM 或 root 权限执行任意命令
AiSOC 7.2.0 至 12.0.0 之前的版本中,actions 服务在构造 CrowdStrike Real Time Response 命令字符串时,未对 action 参数进行转义处理。已认证用户可借此注入单引号,突破引号参数边界,在受管端点上执行任意命令。
影响范围
AiSOC 7.2.0 起至 12.0.0 之前的版本;具体受影响版本范围以官方公告为准。
漏洞详情
漏洞类型为命令注入。成因是 crowdstrike_rtr.py 与 endpoint.py 在拼接 CrowdStrike RTR 命令字符串时,直接插值 file_path、path、script_name、script_args 等未转义参数。攻击者通过在这些参数中注入单引号闭合原有引号参数,即可追加并执行任意系统命令。
利用条件与风险
利用前提是攻击者拥有 AiSOC 的已认证账户,并能触发 actions 服务下发 RTR 命令。成功利用后可在受管端点获得 SYSTEM 或 root 权限,实战风险极高。
修复建议
建议升级至 AiSOC 12.0.0 或更高版本;若无法立即升级,应限制 actions 服务访问权限并审计相关参数输入。具体修复方案以厂商官方公告为准。
AiSOC versions 7.2.0 before 12.0.0 contain a command injection vulnerability in the actions service that builds CrowdStrike Real Time Response command strings by interpolating unescaped action parameters in crowdstrike_rtr.py and endpoint.py. Authenticated users can inject single quotes into file_path, path, script_name, or script_args parameters to break out of quoted arguments and execute arbitrary commands on managed endpoints with SYSTEM or root privileges.