Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library which has a buffer overflow vulnerability that may allow users able to connect to a named pipe to execute commands on the Windows agent machine.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/jenkinsci-cert/nvd-cwe