Описание
GitHub: CVE-2026-32631 'git clone' from manipulated repositories can leak NTLM hashes
CVE-2026-32631 is regarding a vulnerability where it is possible to obtain a user's NTLM hash by tricking them into cloning a malicious repository, or checking out a malicious branch that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. GitHub created this CVE on their behalf. The documented Visual Studio updates incorporate updates in Git which address this vulnerability.
Please see CVE-2026-32631 for more information.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) | ||
| Microsoft Visual Studio 2019 version 16.4 (includes 16.0 - 16.3) | ||
| Microsoft Visual Studio 2022 version 17.12 | ||
| Microsoft Visual Studio 2022 version 17.14 | ||
| Microsoft Visual Studio 2026 version 18.4 |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
7.4 High
CVSS3
Связанные уязвимости
Git for Windows is the Windows port of Git. Versions prior to 2.53.0.windows.3 do not have protections that prevent attackers from obtaining a user's NTLM hash. The NTLM hash can be obtained by tricking users into cloning a malicious repository, or checking out a malicious branch, that accesses an attacker-controlled server. By default, NTLM authentication does not need any user interaction. By brute-forcing the NTLMv2 hash (which is expensive, but possible), credentials can be extracted. This issue has been fixed in version 2.53.0.windows.3.
Уязвимость функции git_clone() распределенной системы управления версиями Git, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
7.4 High
CVSS3