PT-2023-5951 · Git · Git For Windows
Veath1
·
Published
2023-02-14
·
Updated
2023-08-02
·
CVE-2023-22743
CVSS v3.1
7.2
High
| Vector | AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Git for Windows versions prior to 2.39.2
Description
The issue is related to the Windows port of the revision control system Git. By carefully crafting a DLL and placing it into a subdirectory of a specific name next to the Git for Windows installer, Windows can be tricked into side-loading the DLL. This potentially allows users with local write access to place malicious payloads in a location where automated upgrades might run the Git for Windows installer with elevation.
Recommendations
For Git for Windows versions prior to 2.39.2, update to version 2.39.2 to resolve the issue.
As a temporary workaround, never leave untrusted files in the Downloads folder or its sub-folders before executing the Git for Windows installer, or move the installer into a different directory before executing it.
Exploit
Fix
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Git For Windows