CVE-2022-24767

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
12/04/2022
Last modified:
01/10/2024

Description

GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microsoft:visual_studio_2017:*:*:*:*:*:*:*:* 15.0 (including) 15.9.46 (excluding)
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* 16.0 (including) 16.7.27 (excluding)
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* 16.8 (including) 16.9.19 (excluding)
cpe:2.3:a:microsoft:visual_studio_2019:*:*:*:*:*:*:*:* 16.10 (including) 16.11.12 (excluding)
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* 17.0 (including) 17.0.8 (excluding)
cpe:2.3:a:microsoft:visual_studio_2022:*:*:*:*:*:*:*:* 17.1.0 (including) 17.1.4 (excluding)
cpe:2.3:a:git_for_windows_project:git_for_windows:*:*:*:*:*:*:*:* 2.35.2 (excluding)