CVE-2024-23749 EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 4.7% (pctl 92)
Patch early
A public exploit exists.
Description
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-2390). This allows an attacker to add inputs inside the filename variable, leading to arbitrary code execution.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.69% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2024-02-09 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| 9bis | kitty |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | KiTTY 0.76.1.13 - Command Injection | 2024-03-14 |
References
- http://packetstormsecurity.com/files/177031/KiTTY-0.76.1.13-Command-Injection.html
- http://seclists.org/fulldisclosure/2024/Feb/13
- http://seclists.org/fulldisclosure/2024/Feb/14
- https://blog.defcesco.io/CVE-2024-23749
- http://packetstormsecurity.com/files/177031/KiTTY-0.76.1.13-Command-Injection.html
- http://seclists.org/fulldisclosure/2024/Feb/13
- http://seclists.org/fulldisclosure/2024/Feb/14
- https://blog.defcesco.io/CVE-2024-23749
→ the Explorer · watch your stack · NVD