#VU72243 Untrusted search path in Git for Windows - CVE-2023-23618
Published: February 15, 2023
Git for Windows
Git for Windows
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to "gitk" on Windows executes binaries from the current working directory. A remote attacker can trick the victim into placing a malicious binary into the working directory using social engineering and trick users into running untrusted code.