PT-2019-14303 · Tree-Kill · Treekill

Published

2019-12-18

·

Updated

2022-05-24

·

CVE-2019-15599

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions tree-kill versions prior to 1.2.2
Description A Code Injection exists in tree-kill on Windows, allowing remote code execution when an attacker controls the input into the command. The issue arises from the failure to sanitize values passed to the kill function, which may allow attackers to run arbitrary commands on the server. This issue only affects Windows systems.
Recommendations Upgrade to version 1.2.2 or later. As a temporary workaround, consider restricting the use of the kill function in tree-kill until a patch is available. Avoid using user-controlled input in the kill function to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-15599
GHSA-884P-74JH-XRG2
GHSA-MXQ6-VRRR-PPMG

Affected Products

Treekill