CVE-2023-22743

CWE-4263 documents3 sources
Severity
7.3HIGH
EPSS
0.1%
top 73.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMar 14

Description

Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Windows can be tricked into side-loading said DLL. This potentially allows users with local write access to place malicious payloads in a location where automated upgrades might run the Git for Windows installer with elevation. Version 2.39.2 contains a patch for

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:HExploitability: 0.6 | Impact: 6.0

Affected Packages2 packages

CVEListV5git-for-windows/git< 2.39.2
NVDgit< 2.39.2

Patches

🔴Vulnerability Details

1
CVEList
Git for Windows' installer is susceptible to DLL side loading attacks2023-02-14

📋Vendor Advisories

1
Microsoft
GitHub: CVE-2023-22743 Git for Windows Installer Elevation of Privilege Vulnerability2023-03-14