« Volver al listado

CVE-2026-28211

Estado: AplazadaAlta (7.8)—

The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions 2.0 through 8.0 in the Log Reader feature of this add-on. A maliciously crafted log file can lead to arbitrary code execution when a user reads it with log reader commands. The log reading command process speech log entries in an unsafe manner. Python expressions embedded in the log may be evaluated when when speech entries are read with log reading commands.

Leer descripción completaMostrar menos

An attacker can exploit this by convincing a user to open a malicious crafted log file and to analyze it using the log reading commands. When the log is read, attacker-controlled code may execute with the privileges of the current user. This issue does not require elevated privileges and relies solely on user interaction (opening the log file). Version 9.0 contains a fix for the issue. As a workaround, avoid using log reading commands, or at least, commands to move to next/previous log message (any message or commands for each type of message). For more security, one may disable their gestures in the input gesture dialog.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:L/UI:R indica ejecución en cliente con interacción del usuario (apertura de fichero log malicioso). Evaluación de expresiones Python en log = ejecución de código arbitrario. Acceso a logs implica lectura de datos del sistema.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-28211",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-28211",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-02-27T18:52:04.198689Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "CyrilleB79",
          "product": "NVDA-Dev-Test-Toolbox",
          "versions": [
            {
              "status": "affected",
              "version": ">= 2.0, < 9.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-02-26T23:16:35.600",
  "references": [
    {
      "url": "https://github.com/CyrilleB79/NVDA-Dev-Test-Toolbox/commit/21a0544432b08971b5d18320e8256be12c610bea",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/CyrilleB79/NVDA-Dev-Test-Toolbox/releases/tag/V9.0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/CyrilleB79/NVDA-Dev-Test-Toolbox/security/advisories/GHSA-39pg-6xpm-mjgf",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-943"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The NVDA Dev & Test Toolbox is an NVDA add-on for gathering tools to help NVDA development and testing. A vulnerability exists in versions 2.0 through 8.0 in the Log Reader feature of this add-on. A maliciously crafted log file can lead to arbitrary code execution when a user reads it with log reader commands. The log reading command process speech log entries in an unsafe manner. Python expressions embedded in the log may be evaluated when when speech entries are read with log reading commands. An attacker can exploit this by convincing a user to open a malicious crafted log file and to analyze it using the log reading commands. When the log is read, attacker-controlled code may execute with the privileges of the current user.\nThis issue does not require elevated privileges and relies solely on user interaction (opening the log file). Version 9.0 contains a fix for the issue. As a workaround, avoid using log reading commands, or at least, commands to move to next/previous log message (any message or commands for each type of message). For more security, one may disable their gestures in the input gesture dialog."
    },
    {
      "lang": "es",
      "value": "La Caja de Herramientas de Desarrollo y Prueba de NVDA es un complemento de NVDA para recopilar herramientas que ayuden al desarrollo y las pruebas de NVDA. Existe una vulnerabilidad en las versiones 2.0 a 8.0 en la función Lector de Registros de este complemento. Un archivo de registro creado con fines maliciosos puede conducir a la ejecución de código arbitrario cuando un usuario lo lee con comandos del lector de registros. El comando de lectura de registros procesa las entradas de registro de voz de manera insegura. Las expresiones de Python incrustadas en el registro pueden ser evaluadas cuando las entradas de voz son leídas con comandos de lectura de registros. Un atacante puede explotar esto convenciendo a un usuario de abrir un archivo de registro creado con fines maliciosos y de analizarlo usando los comandos de lectura de registros. Cuando se lee el registro, el código controlado por el atacante puede ejecutarse con los privilegios del usuario actual.\nEste problema no requiere privilegios elevados y se basa únicamente en la interacción del usuario (abrir el archivo de registro). La versión 9.0 contiene una corrección para el problema. Como solución alternativa, evite usar los comandos de lectura de registros, o al menos, los comandos para moverse al mensaje de registro siguiente/anterior (cualquier mensaje o comandos para cada tipo de mensaje). Para mayor seguridad, se pueden deshabilitar sus gestos en el diálogo de gestos de entrada."
    }
  ],
  "lastModified": "2026-06-17T10:28:20.417",
  "sourceIdentifier": "security-advisories@github.com"
}