CRITICAL

CVE-2019-16941

CVSS v3

9.8

CRITICAL

EPSS Score

22.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).

Technical details

Published
9/28/2019

Frequently asked questions

What is CVE-2019-16941?

NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).

Is CVE-2019-16941 actively exploited?

Active exploitation of CVE-2019-16941 has not been confirmed. The EPSS score is 22.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-16941?

CVE-2019-16941 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-16941 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.