Windows libarchive Remote Code Execution Vulnerability
Published Jan 9, 2024
7.5
HIGHCVSS 3.1
EPSS 72.16%
Description
Windows libarchive Remote Code Execution Vulnerability
Affected products
-
- Version 10.0.22631.0StatusaffectedConstraints<10.0.22631.3007
- Version
-
- Version 10.0.22621.0StatusaffectedConstraints<10.0.22621.3007
- Version
-
- Version 10.0.22631.0StatusaffectedConstraints<10.0.22631.3007
- Version
-
- Version 10.0.25398.0StatusaffectedConstraints<10.0.25398.643
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Windows 11 Version 23H2 | n/a |
| ||||||
| Microsoft | Windows 11 version 22H2 | n/a |
| ||||||
| Microsoft | Windows 11 version 22H3 | n/a |
| ||||||
| Microsoft | Windows Server 2022, 23H2 Edition (Server Core installation) | n/a |
|
- < 10.0.22621.3007
- < 10.0.22621.3007
- < 10.0.22631.3007
- < 10.0.22631.3007
- n/a
No data.
Red Hat Enterprise Linux 10
libarchive
Not affected
Red Hat Enterprise Linux 6
libarchive
Not affected
Red Hat Enterprise Linux 7
libarchive
Not affected
Red Hat Enterprise Linux 8
libarchive
Not affected
Red Hat Enterprise Linux 9
libarchive
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | libarchive | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libarchive | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libarchive | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libarchive | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libarchive | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The CVE-2024-20697 was assigned to track this issue in Windows systems and the CVE-2024-26256 was assigned to track the issue in libarchive upstream. See the CVE-2024-26256 page for more information about this issue at https://access.redhat.com/security/cve/CVE-2024-26256.
References (11)
- http://www.openwall.com/lists/oss-security/2024/06/04/2
- http://www.openwall.com/lists/oss-security/2024/06/05/1
- https://access.redhat.com/security/cve/CVE-2024-20697 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2290445 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-18412 Advisory
- https://github.com/advisories/GHSA-w6xv-37jv-7cjr
- https://github.com/libarchive/libarchive/pull/2135
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-20697 vendor-advisoryPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-20697
- https://www.cve.org/CVERecord?id=CVE-2024-20697
- https://www.zerodayinitiative.com/blog/2024/4/17/cve-2024-20697-windows-libarchive-remote-code-execution-vulnerability
Change history (0)
No recorded changes yet.