CVE-2023-22743
Summary
| CVE | CVE-2023-22743 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-14 21:15:00 UTC |
| Updated | 2023-08-02 19:27:00 UTC |
| Description | Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully crafting DLL and putting into a subdirectory of a specific name living next to the Git for Windows installer, Windows can be tricked into side-loading said DLL. This potentially allows users with local write access to place malicious payloads in a location where automated upgrades might run the Git for Windows installer with elevation. Version 2.39.2 contains a patch for this issue. Some workarounds are available. Never leave untrusted files in the Downloads folder or its sub-folders before executing the Git for Windows installer, or move the installer into a different directory before executing it. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| About Side-by-Side Assemblies - Win32 apps | Microsoft Learn |
MISC |
learn.microsoft.com |
|
| Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account · Advisory · git-for-windows/git · GitHub |
MISC |
github.com |
|
| Hijack Execution Flow: DLL Side-Loading, Sub-technique T1574.002 - Enterprise | MITRE ATT&CK® |
MISC |
attack.mitre.org |
|
| Enabling Visual Styles - Win32 apps | Microsoft Learn |
MISC |
learn.microsoft.com |
|
| Release Git for Windows 2.39.2 · git-for-windows/git · GitHub |
MISC |
github.com |
|
| Git for Windows' installer is susceptible to DLL side loading attacks · Advisory · git-for-windows/git · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 91992 Microsoft Visual Studio Security Updates for March 2023