PT-2023-26807 · Conemu · Conemu

Maximus5

·

Published

2023-09-12

·

Updated

2023-10-05

·

CVE-2023-39150

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ConEmu versions prior to commit 230724
Description The issue is related to the incorrect sanitization of title responses for control characters, potentially leading to arbitrary code execution. This is connected to an incomplete fix for a previous issue.
Recommendations For ConEmu versions prior to commit 230724, update to a version that includes the commit 230724 or later to resolve the issue. As a temporary workaround, consider disabling the handling of title responses until a patch is available. Restrict access to potentially vulnerable features to minimize the risk of exploitation.

Fix

Related Identifiers

CVE-2023-39150

Affected Products

Conemu