CVE-2019-9197

The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
unity3dunity_editor
5.6.0 ≤
𝑥
< 5.6.7f1
unity3dunity_editor
2017.4.22 ≤
𝑥
< 2017.4.22f1
unity3dunity_editor
2018.2.21 ≤
𝑥
< 2018.2.21f1
unity3dunity_editor
2018.3.7 ≤
𝑥
< 2018.3.7f1
unity3dunity_editor
2019.1.0 ≤
𝑥
< 2019.1.0b5
unity3dunity_editor
2019.2.0 ≤
𝑥
< 2019.2.0a7
𝑥
= Vulnerable software versions