CVE-2024-40644 affects gitoxide's gix-path component, specifically on Windows systems, where it can be tricked into executing a malicious git.exe from an untrusted location. The vulnerability is rated Medium (CVSS 6.8) due to its potential for privilege escalation and code execution, primarily on 32-bit Windows systems where a limited user can create a specific directory to house the malicious executable. While the attack requires user interaction and a specific system configuration (git not in PATH), it could lead to high impact on confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Byron | Gitoxide | < 0.10.9CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.