Vulnerability Description
ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maximus5 | Conemu | < 23.07.24 |
References
- https://gist.github.com/dgl/081cf503dc635df39d844e058a6d4c88Third Party Advisory
- https://github.com/Maximus5/ConEmu/commit/60683a186628ffaa7689fcb64b3c38ced69287Patch
- https://gist.github.com/dgl/081cf503dc635df39d844e058a6d4c88Third Party Advisory
- https://github.com/Maximus5/ConEmu/commit/60683a186628ffaa7689fcb64b3c38ced69287Patch
FAQ
What is CVE-2023-39150?
CVE-2023-39150 is a vulnerability with a CVSS score of 9.8 (CRITICAL). ConEmu before commit 230724 does not sanitize title responses correctly for control characters, potentially leading to arbitrary code execution. This is related to an incomplete fix for CVE-2022-46387...
How severe is CVE-2023-39150?
CVE-2023-39150 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-39150?
Check the references section above for vendor advisories and patch information. Affected products include: Maximus5 Conemu.