Search Path Vulnerability in NSA Ghidra Software
CVE-2019-17664

7.8HIGH

Key Information:

Vendor

Nsa

Status
Vendor
CVE Published:
16 October 2019

What is CVE-2019-17664?

NSA Ghidra, a software reverse engineering suite, has a vulnerability stemming from its handling of the Java process working directory. When Ghidra is executed from a specified path, this directory becomes untrusted. Consequently, when utilizing the Python interpreter via the Ghidra Codebrowser, the application attempts to run cmd.exe from this working directory, which can lead to potential arbitrary command execution by malicious actors manipulating the search path.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.