Loading
Salesforce から送信されるメールは、承認済ドメインからのみとなります続きを読む

CVE for a vulnerability impacting Salesforce CLI - CVE-2025-9844

公開日: Sep 23, 2025
説明

The Salesforce-CLI installer (sf-x64.exe) is vulnerable to arbitrary code execution, privilege escalation, and SYSTEM-level access. This vulnerability arises from improper handling of the executable file path, especially when combined with social engineering tactics.

 

Affected Versions: Salesforce-CLI versions prior to 2.106.6 are impacted.

 

This vulnerability affects only those customers who downloaded the software from an untrusted source, rather than directly from the official Salesforce site. Untrusted downloads may contain a malicious file in the local directory, which could be executed instead of the legitimate files in the specified file path.

解決策

If you downloaded salesforce-cli from an untrusted source, scan your local system for malware or suspicious activity.

ナレッジ記事番号

005224301

 
読み込み中
Salesforce Help | Article