Untrusted search path in Git for Windows - CVE-2023-29012

 

Untrusted search path in Git for Windows - CVE-2023-29012

Published: April 25, 2023 / Updated: June 14, 2023


Vulnerability identifier: #VU75483
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2023-29012
CWE-ID: CWE-426
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Git for Windows
Affected software:
Git for Windows

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insecure implementation of the Git CMD function, which automatically searches and  executes the doskey.exe file from the current working directory. A remote attacker can trick the victim into placing a malicious file and tricking the victim into executing the CMD command in the directory with malicious file.

How to mitigate CVE-2023-29012

Install updates from vendor's website.

Sources