TrueConf Server exposes an undocumented function on 4307/TCP without requiring authentication. A remote attacker with network access can call that function and supply an attacker-controlled script for execution on the server. Kaspersky describes the initially received script as running in an isolated environment where operating system functions are not accessible by default. The implementation detail that leaves the function unauthenticated, and the exact script format, have not been publicly described. In the observed campaign, this vulnerability was used as an initial stage and combined with a separate vulnerability to escape the isolated environment and execute operating-system commands.