Opening SecureFlowOllama Windows Auto-Update Persistent RCE
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Striga and CERT Polska aidefend-sf0023

Ollama Windows Auto-Update Persistent RCE

  • AI Supply Chain
  • Edge & Client AI
  • System Compromise & RCE
  • Model Poisoning & Integrity

Striga and CERT Polska documented a chained flaw in Ollama for Windows 0.12.10 through 0.22.0: attacker-influenced update responses could provide malicious ETag or Content-Disposition path values, the updater could write a payload outside its staging directory such as the Windows Startup folder, Windows signature verification was a no-op, and the payload could run persistently on later logins. Ollama first shipped the hardened update flow in v0.23.3.

Mapped threat techniques

Source