Home/Product/git for windows project git for windows
Product

git for windows project git for windows

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-66413
<= 2.53.0
Git for Windows is the Windows port of Git. Prior to 2.53.0(2), it is possible to obtain a user's NTLM hash by tricking them into
7.4HIGH
CVE-2023-29012
< 2.40.1
Git for Windows is the Windows port of Git. Prior to version 2.40.1, any user of Git CMD who starts the command in an untrusted di
7.2HIGH
CVE-2023-29011
< 2.40.1
Git for Windows, the Windows port of Git, ships with an executable called connect.exe, which implements a SOCKS5 proxy that can
7.5HIGH
CVE-2023-25815
< 2.40.1
In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expect
3.3LOW
CVE-2023-23618
< 2.39.2
Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, when gitk is ru
8.6HIGH
CVE-2023-22743
< 2.39.2
Git for Windows is the Windows port of the revision control system Git. Prior to Git for Windows version 2.39.2, by carefully craf
7.2HIGH
CVE-2022-31012
< 2.37.1
Git for Windows is a fork of Git that contains Windows-specific patches. This vulnerability in versions prior to 2.37.1 lets Git f
8.2HIGH
CVE-2022-24767
< 2.35.2
GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account.
7.8HIGH
CVE-2021-46101
<= 2.34.1
In Git for windows through 2.34.1 when using git pull to update the local warehouse, git.cmd can be run directly.
7.5HIGH
CVE-2018-11235
<= 2.17.1
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code exec
7.8HIGH
CVE-2016-9274
>= 1.0.0 and <= 1.9.4
Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file i
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin