PT-2019-14303 · Tree-Kill · Treekill
Publicado
2019-12-18
·
Atualizado
2022-05-24
·
CVE-2019-15599
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
tree-kill versions prior to 1.2.2
Description
A Code Injection exists in tree-kill on Windows, allowing remote code execution when an attacker controls the input into the command. The issue arises from the failure to sanitize values passed to the
kill function, which may allow attackers to run arbitrary commands on the server. This issue only affects Windows systems.Recommendations
Upgrade to version 1.2.2 or later. As a temporary workaround, consider restricting the use of the
kill function in tree-kill until a patch is available. Avoid using user-controlled input in the kill function to minimize the risk of exploitation.Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Treekill