Security Advisory

CVE-2026-74801

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-17 11:04:36
Last updated 2026-08-17 15:16:34
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.