PT-2022-2372 · Microsoft+10 · Powershell+11

·

CVE-2022-24765

·

Published

2022-04-12

·

Updated

2026-08-17

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Git for Windows versions prior to 2.35.2 Git versions prior to the fix for this issue, exact version not specified
Description The issue is related to the possibility of creating a .git folder in a shared location, which could be exploited by an attacker to run arbitrary commands. This affects users working on multi-user machines where untrusted parties have write access to the same hard disk. The vulnerability can be exploited when Git operations are run outside a repository, and Git respects any config in the .git directory. Users of IDEs such as Visual Studio, Git Bash, and PowerShell are vulnerable. The estimated number of potentially affected devices is not specified.
Recommendations For Git for Windows versions prior to 2.35.2, update to version 2.35.2 or later to resolve the issue. For users unable to upgrade, create the folder .git on all drives where Git commands are run, and remove read/write access from those folders as a workaround. Alternatively, define or extend GIT CEILING DIRECTORIES to cover the parent directory of the user profile, e.g., C:Users if the user profile is located in C:Usersmy-user-name. As a temporary workaround, consider restricting access to the .git directory to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2319
ALSA-2023:2859
ALSA-2023_2319
ALSA-2023_2859
ALT-PU-2022-1705
ALT-PU-2022-1718
ALT-PU-2023-4135
BDU:2022-02723
BIT-GIT-2022-24765
CESA-2023_2859
CVE-2022-24765
DLA-3239-1
DLA-3239-2
DSA-5332-1
GHSA-VW2C-22J4-2FH2
MGASA-2022-0147
OESA-2022-1676
OPENSUSE-SU-2022_1260-1
OPENSUSE-SU-2022_1484-1
OPENSUSE-SU-2022_3283-1
OPENSUSE-SU-2022_3494-1
OPENSUSE-SU-2022_3495-1
OPENSUSE-SU-2024:12003-1
OPENSUSE-SU-2024:12005-1
OPENSUSE-SU-2024:12223-1
RHSA-2023:2319
RHSA-2023:2859
RHSA-2023_2319
RHSA-2023_2859
RHSA-2024:0407
SUSE-SU-2022:1260-1
SUSE-SU-2022:1306-1
SUSE-SU-2022:1484-1
SUSE-SU-2022:3283-1
SUSE-SU-2022:3494-1
SUSE-SU-2022:3495-1
SUSE-SU-2022_1260-1
SUSE-SU-2022_1306-1
SUSE-SU-2022_1484-1
SUSE-SU-2022_3283-1
SUSE-SU-2022_3494-1
USN-5376-1
USN-5376-2
USN-5376-3

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Apple Macos
Powershell
Red Hat
Red Os
Suse
Ubuntu
Visual Studio