CVE-2023-23618
Prior to Git for Windows version 2.39.2, when `gitk` is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.39%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, when `gitk` is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code. A patch is available in version 2.39.2. As a workaround, avoid using `gitk` (or Git GUI's "Visualize History" functionality) in clones of untrusted repositories.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.39% probability · 32th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-426
- Affected
- git for windows project/git for windows
- Source
- security-advisories@github.com
References
- https://github.com/git-for-windows/git/commit/49a8ec9dac3cec6602f05fed1b3f80a549c8c05cPatch
- https://github.com/git-for-windows/git/releases/tag/v2.39.2.windows.1Release Notes
- https://github.com/git-for-windows/git/security/advisories/GHSA-wxwv-49qw-35pmVendor Advisory
- https://wiki.tcl-lang.org/page/execNot Applicable
- https://github.com/git-for-windows/git/commit/49a8ec9dac3cec6602f05fed1b3f80a549c8c05cPatch
- https://github.com/git-for-windows/git/releases/tag/v2.39.2.windows.1Release Notes
- https://github.com/git-for-windows/git/security/advisories/GHSA-wxwv-49qw-35pmVendor Advisory
- https://wiki.tcl-lang.org/page/execNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.