First published: Fri Nov 11 2016(Updated: )
Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Git for Windows | >=1.0.0<=1.9.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-9274 is considered medium as it allows local users to gain privileges.
To fix CVE-2016-9274, ensure that Git is updated to version 2.x or later.
CVE-2016-9274 affects users of Git for Windows version 1.x, specifically those using versions between 1.0.0 and 1.9.4.
CVE-2016-9274 is an untrusted search path vulnerability that can lead to privilege escalation.
An attacker can exploit CVE-2016-9274 by placing a Trojan horse git.exe file in the current working directory, allowing them to execute code with elevated privileges.