CVE-2021-45444
published 2022-02-14CVE-2021-45444: In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs…
PriorityP342high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.98%
78.3th percentile
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | >= 11.0 < 11.6.6 | 11.6.6 |
| apple | macos | >= 12.0.0 < 12.4 | 12.4 |
| apple | macos_big_sur | — | — |
| apple | macos_monterey | — | — |
| apple | security_update_2022-004_catalina | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | zsh | < zsh 5.8.1-1 (bookworm) | zsh 5.8.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_zsh_5.9-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_zsh_5.8.1-1_on_cbl_mariner_1.0 | — | — |
| zsh | zsh | < 5.8.1 | 5.8.1 |
| zsh | zsh | >= 0 < 5.8-6+deb11u1 | 5.8-6+deb11u1 |
| zsh | zsh | >= 0 < 5.8.1-1 | 5.8.1-1 |
| zsh | zsh | >= 0 < 5.8.1-1 | 5.8.1-1 |
| zsh | zsh | >= 0 < 5.8.1-1 | 5.8.1-1 |
| zsh | zsh | >= 0 < 5.4.2-3ubuntu3.2 | 5.4.2-3ubuntu3.2 |
| zsh | zsh | >= 0 < 5.8-3ubuntu1.1 | 5.8-3ubuntu1.1 |
| zsh | zsh | >= 0 < 5.1.1-1ubuntu2.3+esm1 | 5.1.1-1ubuntu2.3+esm1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2021-45444: macOS Big Sur 11.6.6
vendor_apple·2022-05-16·CVSS 7.8
CVE-2021-45444 [HIGH] CVE-2021-45444: macOS Big Sur 11.6.6
Apple Security Update: About the security content of macOS Big Sur 11.6.6
Product: macOS Big Sur
Version: 11.6.6
CVE: CVE-2021-45444
Component: CVE-2021-45444
Apple
CVE-2021-45444: Security Update 2022-004 Catalina
vendor_apple·2022-05-16·CVSS 7.8
CVE-2021-45444 [HIGH] CVE-2021-45444: Security Update 2022-004 Catalina
Apple Security Update: About the security content of Security Update 2022-004 Catalina
Product: Security Update 2022-004 Catalina
CVE: CVE-2021-45444
Component: CVE-2021-45444
Apple
CVE-2021-45444: macOS Monterey 12.4
vendor_apple·2022-05-16·CVSS 7.8
CVE-2021-45444 [HIGH] CVE-2021-45444: macOS Monterey 12.4
Apple Security Update: About the security content of macOS Monterey 12.4
Product: macOS Monterey
Version: 12.4
CVE: CVE-2021-45444
Component: CVE-2021-45444
Ubuntu
Zsh vulnerabilities
vendor_ubuntu·2022-03-14·CVSS 7.8
CVE-2021-45444 [HIGH] Zsh vulnerabilities
Title: Zsh vulnerabilities
Summary: Several security issues were fixed in Zsh.
Sam Foxman discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this issue to regain dropped privileges.
(CVE-2019-20044)
It was discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2021-45444)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
zsh: Prompt expansion vulnerability
vendor_redhat·2022-02-12·CVSS 7.8
CVE-2021-45444 [HIGH] CWE-77 zsh: Prompt expansion vulnerability
zsh: Prompt expansion vulnerability
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
A vulnerability was found in zsh in the parsecolorchar() function of prompt.c file. This flaw allows an attacker to perform code execution if they control a command output inside the prompt, as stated by a %F%K argument. This occurs because of recursive PROMPT_SUBST expansion.
Statement: Red Hat Enterprise Linux 6 and 7 are not affected, because the vulnerable function is not present in the code-base.
Red Hat Product Security has rated this issue as having a Moderate security impact, and the issue is not currently planned to be addressed in future upda
Microsoft
In zsh before 5.8.1 an attacker can achieve code execution if they control a command output inside the prompt as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
vendor_msrc·2022-02-08·CVSS 7.8
CVE-2021-45444 [HIGH] In zsh before 5.8.1 an attacker can achieve code execution if they control a command output inside the prompt as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
In zsh before 5.8.1 an attacker can achieve code execution if they control a command output inside the prompt as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the
Debian
CVE-2021-45444: zsh - In zsh before 5.8.1, an attacker can achieve code execution if they control a co...
vendor_debian·2021·CVSS 7.8
CVE-2021-45444 [HIGH] CVE-2021-45444: zsh - In zsh before 5.8.1, an attacker can achieve code execution if they control a co...
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
Scope: local
bookworm: resolved (fixed in 5.8.1-1)
bullseye: resolved (fixed in 5.8-6+deb11u1)
forky: resolved (fixed in 5.8.1-1)
sid: resolved (fixed in 5.8.1-1)
trixie: resolved (fixed in 5.8.1-1)
OSV
zsh vulnerabilities
osv·2022-03-14·CVSS 7.8
CVE-2019-20044 [HIGH] zsh vulnerabilities
zsh vulnerabilities
Sam Foxman discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this issue to regain dropped privileges.
(CVE-2019-20044)
It was discovered that Zsh incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2021-45444)
GHSA
GHSA-735j-r9q6-48mw: In zsh before 5
ghsa_unreviewed·2022-02-15
CVE-2021-45444 [HIGH] GHSA-735j-r9q6-48mw: In zsh before 5
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
OSV
CVE-2021-45444: In zsh before 5
osv·2022-02-14·CVSS 7.8
CVE-2021-45444 [HIGH] CVE-2021-45444: In zsh before 5
In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/35http://seclists.org/fulldisclosure/2022/May/38https://lists.debian.org/debian-lts-announce/2022/02/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2P3LPMGENEHKDWFO4MWMZSZL6G7Y4CV7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWF3EXNBX5SVFDBL4ZFOD4GJBWFUKWN4/https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256https://support.apple.com/kb/HT213257https://vuln.ryotak.me/advisories/63https://www.debian.org/security/2022/dsa-5078https://zsh.sourceforge.io/releases.htmlhttp://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/35http://seclists.org/fulldisclosure/2022/May/38https://lists.debian.org/debian-lts-announce/2022/02/msg00020.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2P3LPMGENEHKDWFO4MWMZSZL6G7Y4CV7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWF3EXNBX5SVFDBL4ZFOD4GJBWFUKWN4/https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256https://support.apple.com/kb/HT213257https://vuln.ryotak.me/advisories/63https://www.debian.org/security/2022/dsa-5078https://zsh.sourceforge.io/releases.html
2022-02-14
Published