VulnerabilityModified
CVE-2023-39150
ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution.
CRITICAL 9.8EPSS 0.80%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.80%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.80% probability · 55th percentile
- CISA KEV
- Not listed
- Affected
- maximus5/conemu
- Source
- cve@mitre.org
References
- https://gist.github.com/dgl/081cf503dc635df39d844e058a6d4c88Third Party Advisory
- https://github.com/Maximus5/ConEmu/commit/60683a186628ffaa7689fcb64b3c38ced69287c1Patch
- https://gist.github.com/dgl/081cf503dc635df39d844e058a6d4c88Third Party Advisory
- https://github.com/Maximus5/ConEmu/commit/60683a186628ffaa7689fcb64b3c38ced69287c1Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.