PT-2023-27313 · Shescape · Shescape
Ericcornelissen
·
Publicado
2023-08-22
·
Atualizado
2023-09-01
·
CVE-2023-40185
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Shescape versions prior to 1.7.4
Description
The issue affects users of Shescape on Windows in a threaded context, allowing attackers to bypass protections by exploiting Shescape's failure to correctly escape for the expected shell. This can occur when the expected default system shell is different from the one actually used, such as when configuring the use of PowerShell but Shescape defaults to escaping for CMD instead.
Recommendations
For versions prior to 1.7.4, upgrade to version 1.7.4 to resolve the issue.
If you are impacted and cannot upgrade immediately, be aware that there is no workaround possible for this vulnerability.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Shescape