CVE-2021-28927

CVE-2021-28927

The text-to-speech engine in libretro RetroArch for Windows 0.11 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems that are used by RetroArch to execute code via command injection using specially a crafted file and directory names.

Source: CVE-2021-28927

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다