CVE-2014-7169
CRITICALEPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
Description
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.
IPFire - CGI Web Interface (Authenticated) Bash Environment Variable Code Injection
by Claudio Viviani · Oct 1, 2014
CUPS Filter - Bash Environment Variable Code Injection (Metasploit)
by Metasploit · Oct 29, 2014
GNU Bash - 'Shellshock' Environment Variable Command Injection
by Stephane Chazelas · Sep 25, 2014
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
by Roberto Suggi Liverani · Apr 2, 2015
Bash - 'Shellshock' Environment Variables Command Injection
by Prakhar Prasad & Subho Halder · Sep 25, 2014
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
by Patrick Pellegrino · Mar 26, 2015
GNU bash 4.3.11 - Environment Variable dhclient
by @0x00string · Oct 2, 2014
Bash CGI - 'Shellshock' Remote Command Injection (Metasploit)
by Fady Mohammed Osman · Oct 6, 2014
PHP < 5.6.2 - 'Shellshock' Safe Mode / disable_functions Bypass / Command Injection
by Ryan King (Starfall) · Nov 3, 2014
Postfix SMTP 4.2.x < 4.2.48 - 'Shellshock' Remote Command Injection
by Phil Blank · Oct 6, 2014
Frequently Asked Questions
Is CVE-2014-7169 in your stack?
O3 detects CVE-2014-7169 across dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.