VDB

GCVE-110-OSM-2025-1081

GCVE-110-OSM-2025-1081
Advisory PublishedCVSS 8.8/10
Vulnetix · Advisory published August 18, 2025
Repository contains an abusive GitHub Actions workflow that establishes unauthorized remote desktop access to a GitHub-hosted Windows runner. It changes operating-system security settings and a local account password before exposing RDP through a public tunneling service. Malicious payload found in: .github/workflows/main.yml The workflow runs on push or manual dispatch using windows-latest. It downloads the official ngrok Windows archive from https://bin.equinox.io/c/bNyj1mQVY4c/ngrok-v3-stable-windows-amd64.zip, extracts it, and authenticates using the NGROK_AUTH_TOKEN repository secret. It enables Terminal Services, enables the Remote Desktop firewall group, configures RDP network-level authentication, changes runneradmin to the hard-coded password P@ssw0rd!, and starts an ngrok TCP tunnel to local port 3389. The assigned public tunnel address is not statically available. The ngrok service is legitimate infrastructure abused by this workflow and is therefore not included as a verified malicious IOC.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Risk Scores

CVSS 3.1
8.8/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
unknownDefault branch commit 4c6b6c9f4208de848ddea7844d4a414fbf96f692 (affected)

Browse GCVE Records

386 records in the GCVE database · Updated September 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›