What happened
Microsoft's open-source UFO agentic automation framework passed caller-controlled parameters into `adb shell` and Windows program-execution paths without argument validation. The adb client joins arguments into a remote command string the Android shell reparses, so `press_key`, `type_text` and `launch_app` (mobile MCP) allow an authenticated API-key holder to append arbitrary commands executed as the Android shell user on an authorized connected device; on Windows, `run_shell` validates only the first token and `explorer.exe` delegation lets a influenced agent call launch an arbitrary executable as the desktop user; `execute_command` (Linux MCP) lets sort/uniq file-output forms create/overwrite files. CISA SSVC lists PoC for the mobile CRITICAL (9.1) and HIGH (8.8) variants.
Why it matters
UFO is Microsoft's flagship agentic UI-automation/computer-use framework; its MCP tool surface is exactly the class attackers target to turn a prompt/manipulated agent into shell execution on mobile devices and developer desktops. Together the four CVEs give an authenticated agent (or attacker-influenced agent workflow) code/command execution on connected devices and the workstation, exposing files, tokens and sessions.
Attack vector
Invoke the mobile MCP press_key/type_text/launch_app tools with shell metacharacters in key_code/text/package_name, or induce run_shell('explorer.exe <attacker path>'); commands execute under the adb shell user / desktop user.
Affected systems
Microsoft UFO < 3.0.9 (CVE-2026-105793 press_key, CVE-2026-105791 run_shell, CVE-2026-105789 execute_command) and < 3.0.10 (CVE-2026-105788 type_text/launch_app)
Mitigation
Upgrade to UFO 3.0.10 (covers 3.0.9 and 3.0.10 fixes); restrict/rotate MCP API keys, restrict ADB-authorized devices, and constrain which agent workflows can invoke these tools.