The bug is remotely exploitable without authentication or user interaction.
Source: Threadpost