Security readout for executives and security teams
Git for Windows could trust a fake Git repository placed at the root of a shared Windows drive. On multi-user machines, another local user could influence Git-aware tools to read attacker-controlled configuration. This is mainly a developer workstation or shared machine risk, not a remote internet-facing service issue. Exposure is most likely on Windows systems running Git for Windows before 2.35.2 where untrusted users can write to the same drive. Single-user locked-down endpoints are lower risk. Developer desktops, shared labs, and multi-user Windows environments deserve priority review. Treat this as a moderate-priority developer endpoint issue. Patch normally, but accelerate for shared Windows workstations, labs, and environments where contractors or multiple users share local disks. It is less urgent than a remotely exploitable server vulnerability. Mitigation focus: Upgrade Git for Windows to version 2.35.2 or later.; If upgrade is delayed, create protected .git folders on drives used with Git.; Remove read and write access from those protective .git folders..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-427: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2022-24765 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N0.85.2Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6MediumVector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/git-for-windows/git/security/advisories/GHSA-vw2c-22j4-2fh2CVE reference
- https://git-scm.com/book/en/v2/Appendix-A%3A-Git-in-Other-Environments-Git-in-BashCVE reference
- https://git-scm.com/docs/git#Documentation/git.txt-codeGITCEILINGDIRECTORIEScodeCVE reference
- FEDORA-2022-e99ae504f5CVE reference · vendor-advisory
- FEDORA-2022-3759ebabd2CVE reference · vendor-advisory
- FEDORA-2022-2fec5f30beCVE reference · vendor-advisory
- https://support.apple.com/kb/HT213261CVE reference
- FEDORA-2022-dfd7e7fc0eCVE reference · vendor-advisory
- FEDORA-2022-2a5de7cb8bCVE reference · vendor-advisory
- [debian-lts-announce] 20221213 [SECURITY] [DLA 3239-1] git security updateCVE reference · mailing-list
- FEDORA-2023-470c7ea49eCVE reference · vendor-advisory
- FEDORA-2023-e3c8abd37eCVE reference · vendor-advisory
- FEDORA-2023-1068309389CVE reference · vendor-advisory
- FEDORA-2023-3ec32f6d4eCVE reference · vendor-advisory
- GLSA-202312-15CVE reference · vendor-advisory
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Uncontrolled Search Path Element
Uncontrolled Search Path Element represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
