HomeSecuritySalesforce CLI Installer: Vulnerability allows malicious code execution

Salesforce CLI Installer: Vulnerability allows malicious code execution

A critical vulnerability in the Salesforce CLI installer (sf-x64.exe) allows attackers to achieve code execution, privilege escalation , and SYSTEM-level access on Windows systems.

Salesforce CLI Installer vulnerability

The vulnerability, tracked as CVE-2025-9844, results from improper handling of executable file paths by the installer, allowing malicious files in place of legitimate binaries when software is obtained from untrusted sources.

The vulnerability exploits the way the Salesforce CLI installer resolves file paths during installation. When sf-x64.exe, it loads various helper executables and DLLs from the current working directory, before returning to the directory containing the installer.

An attacker who places a crafted executable with the same name as a legitimate component (for example, sf-autoupdate.exe or sf-config.dll) in the same folder can cause the installer to load and execute the attacker's code.

See also: CISA: Chrome zero-day vulnerability in KEV Catalog

Since the installer runs with elevated privileges by default, writing registry keys under HKLM and creating services under LocalSystem, the injected code “inherits” SYSTEM-level privileges. As a result, the attacker gains full control of the machine.

Upon execution, the installer loads the malicious sf-autoupdate.exe, which escalates privileges by creating a reverse shell service under the LocalSystem. The attacker then uses the shell to execute commands and successfully retrieve SYSTEM-level output.

Salesforce CLI Installer: Vulnerability allows malicious code execution

Salesforce CLI: Affected versions and protection

All versions of Salesforce CLI prior to 2.106.6 are affected by this vulnerability. Importantly, only users who install the CLI from untrusted mirrors or third-party repositories are at risk. Installations via the official Salesforce website use a signed installer that enforces strict path resolution and integrity checks.

To address the issue, affected users should immediately uninstall any version of CLI obtained from unverified sources and perform a thorough system scan for unknown executables or suspicious services.

See also: Chrome: Vulnerabilities allow data leakage & system crashes

Salesforce has released version 2.106.6 , which fixes the issue . Administrators are advised to enforce installation only from trusted locations and enable Microsoft Defender Application Control (MDAC) policies to restrict the execution of unauthorized binaries in installation directories.

Continuous monitoring of system event logs for unexpected service creation or installer execution under non-standard paths will help in early detection of exploitation attempts.

Constant risk

The CVE-2025-9844 vulnerability in the Salesforce CLI installer highlights one of the most insidious risks for Windows: the abuse of the software installation process to gain privileges SYSTEM . While the issue primarily affects users who download the tool from unofficial sources, its existence demonstrates that even companies with high security standards can be exposed through seemingly “innocent” errors in file path management.

Salesforce CLI Installer: Vulnerability allows malicious code execution

The incident serves as a warning to organizations that rely on cloud development tools: installers elevated are particularly attractive targets, as any integrity check bypass can allow full system control. The CI/CD chain thus becomes the weakest link, especially when developers install tools from mirrors, unofficial repos, or third-party sites for speed reasons.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Vulnerability in SolarWinds Web Help Desk allows RCE execution

The release of the update (2.106.6) is only part of the solution. Enterprises and IT admins need to enforce strict software procurement policies — downloading only from official sources, enforcing digital signature verification, and enabling controls like Microsoft Defender Application Control. In addition, monitoring logs for unusual services or strange installer execution locations can detect exploit attempts before they escalate into a full-blown breach.

The issue shows how critical the principle of Zero Trustandconstant vigilance in the distribution of development tools are. In a world where every developer workstation can be a gateway, proper software installation management becomes a key line of defense.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS