Untrusted search path in Git for Windows - CVE-2023-22743

 

Untrusted search path in Git for Windows - CVE-2023-22743

Published: February 15, 2023


Vulnerability identifier: #VU72244
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-22743
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker co compromise the affected system.

The vulnerability exists due to insecure loading of .dll libraries in Git for Windows installer. A remote attacker can place a malicious DLL file into a subdirectory of a specific name next to the Git for Windows installer (e.g. into a download folder) and execute it on the system by tricking the victim to launch the Git for Windows installer from that directory.


Affected software

Git for Windows
Visual Studio

How to mitigate CVE-2023-22743

Install updates from vendor's website.

Git for Windows - update to 2.39.2.1

External References

Related Security Bulletins