CVE-2016-9274: High severity git for windows vulnerability
Published Nov 11, 2016
·Updated
Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.
Affected Software
1 affected component
Git For Windows Project Git For Windows>=1.0.0<=1.9.4
Remediation
Patch Available
Event History
Nov 11, 2016
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-9274?
The severity of CVE-2016-9274 is considered medium as it allows local users to gain privileges.
2
How do I fix CVE-2016-9274?
To fix CVE-2016-9274, ensure that Git is updated to version 2.x or later.
3
Who is affected by CVE-2016-9274?
CVE-2016-9274 affects users of Git for Windows version 1.x, specifically those using versions between 1.0.0 and 1.9.4.
4
What type of vulnerability is CVE-2016-9274?
CVE-2016-9274 is an untrusted search path vulnerability that can lead to privilege escalation.
5
What can an attacker do with CVE-2016-9274?
An attacker can exploit CVE-2016-9274 by placing a Trojan horse git.exe file in the current working directory, allowing them to execute code with elevated privileges.