PT-2023-27313 · Shescape · Shescape

Ericcornelissen

·

Publicado

2023-08-22

·

Atualizado

2023-09-01

·

CVE-2023-40185

CVSS v3.1

6.5

Média

VetorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Shescape versions prior to 1.7.4
Description The issue affects users of Shescape on Windows in a threaded context, allowing attackers to bypass protections by exploiting Shescape's failure to correctly escape for the expected shell. This can occur when the expected default system shell is different from the one actually used, such as when configuring the use of PowerShell but Shescape defaults to escaping for CMD instead.
Recommendations For versions prior to 1.7.4, upgrade to version 1.7.4 to resolve the issue. If you are impacted and cannot upgrade immediately, be aware that there is no workaround possible for this vulnerability.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-40185
GHSA-J55R-787P-M549

Produtos afetados

Shescape