CVE-2023-22743
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.3 / Impact: 5.9
Source: NVD
Description
Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Windows can be tricked into side-loading said DLL. This potentially allows users with local write access to place malicious payloads in a location where automated upgrades might run the Git for Windows installer with elevation. Version 2.39.2 contains a patch for this issue. Some workarounds are available. Never leave untrusted files in the Downloads folder or its sub-folders before executing the Git for Windows installer, or move the installer into a different directory before executing it.
Affected (1)
Products: Git For Windows Project: Git For Windows
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.39.2 |
References (12)
Source: security-advisories@github.com
Technical Description
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
PatchTechnical DescriptionVendor Advisory
Source: security-advisories@github.com
PatchTechnical DescriptionVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchTechnical DescriptionVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchTechnical DescriptionVendor Advisory
Timeline
No history available yet.