Opening SecureFlowPrompt-to-Shell: Dual RCE Paths in Microsoft Semantic Kernel
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Microsoft (Microsoft Defender Security Research Team) aidefend-sf0004

Prompt-to-Shell: Dual RCE Paths in Microsoft Semantic Kernel

  • Autonomous Agents
  • Tool Integrations & MCP
  • System Compromise & RCE
  • Resource Hijacking & Cost

Microsoft documented two distinct Semantic Kernel prompt-to-host-RCE paths: a Python Search Plugin filter evaluated with eval(), and a .NET SessionsPythonPlugin file-transfer function exposed to model tool calling that could write a payload into the host Startup folder.

Mapped threat techniques

Source