CVE-2023-39150 Information
Sep 16, 2023
cve
Description
ConEmu before commit 230724 does not sanitize title responses correctly for control characters potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/Maximus5/ConEmu/commit/60683a186628ffaa7689fcb64b3c38ced69287c1 https://gist.github.com/dgl/081cf503dc635df39d844e058a6d4c88
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: