Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-47039

Опубликовано: 02 янв. 2024
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS3: 7.8

Описание

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (cmd.exe). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute cmd.exe within the operating system. However, due to path search order issues, Perl initially looks for cmd.exe in the current working directory. This flaw allows an attacker with limited privileges to placecmd.exe in locations with weak permissions, such as C:\ProgramData. By doing so, arbitrary code can be executed when an administrator attempts to use this executable from these compromised locations.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

ignored

only affects Perl for Windows
esm-infra-legacy/trusty

ignored

only affects Perl for Windows
esm-infra-legacy/xenial

ignored

only affects Perl for Windows
esm-infra/bionic

ignored

only affects Perl for Windows
esm-infra/focal

ignored

only affects Perl for Windows
esm-infra/xenial

ignored

end of ESM support, was ignored [only affects Perl for Windows]
focal

ignored

end of standard support, was ignored [only affects Perl for Windows]
jammy

ignored

only affects Perl for Windows
lunar

ignored

end of life, was ignored [only affects Perl for Windows]

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

DNE

esm-apps/bionic

ignored

only affects Perl for Windows
esm-apps/focal

ignored

only affects Perl for Windows
focal

ignored

end of standard support, was ignored [only affects Perl for Windows]
jammy

DNE

lunar

DNE

mantic

DNE

trusty

DNE

upstream

ignored

only affects Perl for Windows

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

ignored

only affects Perl for Windows
esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

ignored

end of life, was ignored [only affects Perl for Windows]
mantic

ignored

end of life, was ignored [only affects Perl for Windows]
trusty

DNE

upstream

ignored

only affects Perl for Windows
xenial

DNE

Показывать по

Ссылки на источники

EPSS

Процентиль: 35%
0.00414
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 2 лет назад

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute `cmd.exe` within the operating system. However, due to path search order issues, Perl initially looks for cmd.exe in the current working directory. This flaw allows an attacker with limited privileges to place`cmd.exe` in locations with weak permissions, such as `C:\ProgramData`. By doing so, arbitrary code can be executed when an administrator attempts to use this executable from these compromised locations.

CVSS3: 7.8
nvd
больше 2 лет назад

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute `cmd.exe` within the operating system. However, due to path search order issues, Perl initially looks for cmd.exe in the current working directory. This flaw allows an attacker with limited privileges to place`cmd.exe` in locations with weak permissions, such as `C:\ProgramData`. By doing so, arbitrary code can be executed when an administrator attempts to use this executable from these compromised locations.

msrc
12 месяцев назад

Perl: perl for windows binary hijacking vulnerability

CVSS3: 7.8
debian
больше 2 лет назад

A vulnerability was found in Perl. This security issue occurs while Pe ...

CVSS3: 7.8
github
больше 2 лет назад

A vulnerability was found in Perl. This security issue occurs while Perl for Windows relies on the system path environment variable to find the shell (`cmd.exe`). When running an executable that uses the Windows Perl interpreter, Perl attempts to find and execute `cmd.exe` within the operating system. However, due to path search order issues, Perl initially looks for cmd.exe in the current working directory. This flaw allows an attacker with limited privileges to place`cmd.exe` in locations with weak permissions, such as `C:\ProgramData`. By doing so, arbitrary code can be executed when an administrator attempts to use this executable from these compromised locations.

EPSS

Процентиль: 35%
0.00414
Низкий

7.8 High

CVSS3