PT-2019-14303 · Tree-Kill · Treekill
Published
2019-12-18
·
Updated
2022-05-24
·
CVE-2019-15599
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
tree-kill versions prior to 1.2.2
Description
A Code Injection exists in tree-kill on Windows, allowing remote code execution when an attacker controls the input into the command. The issue arises from the failure to sanitize values passed to the
kill function, which may allow attackers to run arbitrary commands on the server. This issue only affects Windows systems.Recommendations
Upgrade to version 1.2.2 or later. As a temporary workaround, consider restricting the use of the
kill function in tree-kill until a patch is available. Avoid using user-controlled input in the kill function to minimize the risk of exploitation.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Treekill