Feeds.Feedburner Vulnerability in Anthropic's Claude Cowork Allows Root Command Execution
Article Content
- •Attack chain allows arbitrary command execution as root in Claude Cowork's sandbox.
- •Exploits two weaknesses: privilege escalation and network restriction bypass.
- •Anthropic claims the issue requires local code execution, not a direct vulnerability.
Security researchers at Armadin Inc. have identified an attack chain in Anthropic PBC’s Claude Cowork that allows attackers to execute arbitrary commands as root within its sandbox environment. This vulnerability exploits two weaknesses in the software for Windows, enabling local code execution to escalate privileges. The first weakness involves manipulating a resume flag to bypass user restrictions, while the second allows attackers to override network restrictions, facilitating data exfiltration. Anthropic does not classify this as a security issue, as it requires prior local code execution on the host machine. The vulnerability affects Claude Desktop for Windows version 1.9255.2.0, raising concerns about endpoint security in AI productivity tools. The attack chain has been validated by Armadin, highlighting the risks associated with non-technical user systems running local virtual machines.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…