ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control characters, which allows an attacker to change the title and then execute it as commands.
References
Link | Resource |
---|---|
https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e | Third Party Advisory |
https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md | Release Notes |
https://gist.github.com/dgl/05ca60cdc7efc9e47bbc58d0c952635e | Third Party Advisory |
https://github.com/cmderdev/cmder/blob/master/CHANGELOG.md | Release Notes |
Configurations
History
19 Feb 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-116 |
Information
Published : 2023-03-28 20:15
Updated : 2025-02-19 19:15
NVD link : CVE-2022-46387
Mitre link : CVE-2022-46387
CVE.ORG link : CVE-2022-46387
JSON object : View
Products Affected
maximus5
- conemu
cmder
- cmder
CWE