CVE Tools

CVE-2014-7169

Exploited in the wild. In CISA KEV since 2022‑01‑28. A vendor fix is available.

Published Updated Sources: CVE.org, NVD, BDU

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check which Bash version your systems run (for example, run: bash --version) and identify whether you’re on an affected version.
  2. If you run an affected vendor/platform, upgrade to the fixed version listed for your platform: Alt Linux SPT → update per vendor instructions; EOS → 4.9.12; QTS → 1.1.1.
  3. If you can’t upgrade immediately, reduce exposure by removing or restricting remote features that pass crafted environment variables across a privilege boundary (for example, avoid allowing remote forced command setups that run under different privileges).
  4. After updating, verify Bash is the updated fixed version and review logs for suspicious file-write or execution attempts around remote access services.

What it is

From the CVE record

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

In plain language

Written by AI from the record

CVE-2014-7169 is a very serious Bash bug that lets an attacker misuse specially crafted environment settings to write files or cause severe system damage; if you run affected Bash versions on a server, you should act now.

CVE-2014-7169 is a Bash environment-handling flaw (CWE-78) where malformed function definitions in environment variables can cause Bash to process unintended trailing strings, enabling remote attackers to write files or otherwise impact the system; it was added to CISA KEV with a required patch deadline.

If you're affected

  • Remote file write on servers
  • Full system compromise risk
  • Service outage and downtime
  • Ransomware path via takeover

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS99th
Public exploit
CISA KEV
CISA KEV

Listed as exploited in the wild since 2022-01-28.

US federal agencies must remediate by 2022-07-28.

Apply updates per vendor instructions.
Public exploits

3 sources with a proof of concept or module.

Exploit links, PoCs and Metasploit modules after sign-in
EPSS

100% chance of exploitation activity in the next 30 days, which ranks it in the 99th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

A public exploit existed 47 days before the patch.

  1. OpenVAS check added
  2. EPSS band changehigh → critical
  3. EPSS band changecritical → high
  4. Patch availablerecord updated
  5. Public exploit / PoCsource: packetstorm
  6. Added to CISA KEV

Affected products

And 44 more affected products. See all after sign-in

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Scored 9.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Ibm, not every advisory. This one: actively exploited.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store