CVE-2014-7169
Description
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.
In plain language
AI Act nowCVE-2014-7169 is a very serious Bash bug that lets an attacker misuse specially crafted environment settings to write files or cause severe system damage; if you run affected Bash versions on a server, you should act now.
CVE-2014-7169 is a Bash environment-handling flaw (CWE-78) where malformed function definitions in environment variables can cause Bash to process unintended trailing strings, enabling remote attackers to write files or otherwise impact the system; it was added to CISA KEV with a required patch deadline.
What to do now
- Check which Bash version your systems run (for example, run:
bash --version) and identify whether you’re on an affected version. - If you run an affected vendor/platform, upgrade to the fixed version listed for your platform: Alt Linux SPT → update per vendor instructions; EOS → 4.9.12; QTS → 1.1.1.
- If you can’t upgrade immediately, reduce exposure by removing or restricting remote features that pass crafted environment variables across a privilege boundary (for example, avoid allowing remote forced command setups that run under different privileges).
- After updating, verify Bash is the updated fixed version and review logs for suspicious file-write or execution attempts around remote access services.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2014-7169 and every CVE in our database. Create a free account — no credit card required.
Create Free Account