vendor:
Cmder
by:
Aryan Chehreghani
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Cmder
Affected Version From: 1.3.18
Affected Version To: 1.3.18
Patch Exists: YES
Related CWE:
CPE: a:cmderdev:cmder:1.3.18
Platforms Tested: Windows 10
2021
Cmder Console Emulator 1.3.18 – ‘Cmder.exe’ Denial of Service (PoC)
Cmder is a software package created over absence of usable console emulator on Windows. It is based on ConEmu with major config overhaul, comes with a Monokai color scheme, amazing clink (further enhanced by clink-completions) and a custom prompt layout. A buffer overflow vulnerability exists in Cmder Console Emulator 1.3.18, which requires the execution of a .cmd file type and The created file enters the emulator, That will trigger the buffer overflow condition.
Mitigation:
Update to the latest version of Cmder Console Emulator.