Untrusted search path in Git for Windows - CVE-2023-29012
Published: April 25, 2023 / Updated: June 14, 2023
Vulnerability identifier: #VU75483
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29012
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insecure implementation of the Git CMD function, which automatically searches and executes the doskey.exe file from the current working directory. A remote attacker can trick the victim into placing a malicious file and tricking the victim into executing the CMD command in the directory with malicious file.Affected software
Git for Windows
Visual Studio
Visual Studio
How to mitigate CVE-2023-29012
Install updates from vendor's website.
Git for Windows - update to 2.40.1.1
Visual Studio - addressed in versions 16.11.27 16.11.33801.447, 17.0.22 17.0.33801.228, 17.2.16 17.2.33801.349, 17.4.8 17.4.33801.306, 17.6.3 17.6.33801.468, 2017 version 15.9.55
Visual Studio - addressed in versions 16.11.27 16.11.33801.447, 17.0.22 17.0.33801.228, 17.2.16 17.2.33801.349, 17.4.8 17.4.33801.306, 17.6.3 17.6.33801.468, 2017 version 15.9.55