CVE advisoryCRITICAL
CVE-2021-3331
WinSCP URL Handler Arbitrary Program Execution Vulnerability
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
A vulnerability in WinSCP allows remote attackers to execute arbitrary programs by loading crafted session settings via a URL handler. This could impact systems where WinSCP is configured to handle specific URL types, such as sftp:// URLs, and requires user interaction to trigger.