CVE-2023-23618: gitk can inadvertently call executables in the worktree
Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, when gitk is run on Windows, it potentially runs executables from the current directory inadvertently, which can be exploited with some social engineering to trick users into running untrusted code. A patch is available in version 2.39.2. As a workaround, avoid using gitk (or Git GUI's "Visualize History" functionality) in clones of untrusted repositories.
Other sources
GitHub: CVE-2023-23618 Git for Windows Remote Code Execution Vulnerability
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-23618?
CVE-2023-23618 is a Git for Windows Remote Code Execution Vulnerability.
Who is affected by CVE-2023-23618?
Users of Microsoft Visual Studio 2017, 2019, and 2022 are affected by CVE-2023-23618.
What is the severity of CVE-2023-23618?
CVE-2023-23618 has a severity level of high (7 out of 10).
How can I fix CVE-2023-23618 in Visual Studio 2022 version 17.5?
You can fix CVE-2023-23618 in Visual Studio 2022 version 17.5 by applying the patch provided by Microsoft. You can download the patch from the official Visual Studio website.
Where can I find more information about CVE-2023-23618?
You can find more information about CVE-2023-23618 on the Microsoft Security Response Center website.