CVE-2019-17664 Information
Feb 14, 2021
cve
Description
NSA Ghidra through 9.0.4 uses a potentially untrusted search path. When executing Ghidra from a given path the Java process working directory is set to this path. Then when launching the Python interpreter via the \Ghidra Codebrowser Window Python\ option Ghidra will try to execute the cmd.exe program from this working directory.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Reference
https://github.com/NationalSecurityAgency/ghidra/issues/107
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: