CVE Tools

Description

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

In plain language

AI Act now

CVE-2014-7169 is a very serious Bash bug that lets an attacker misuse specially crafted environment settings to write files or cause severe system damage; if you run affected Bash versions on a server, you should act now.

Executive summary

CVE-2014-7169 is a Bash environment-handling flaw (CWE-78) where malformed function definitions in environment variables can cause Bash to process unintended trailing strings, enabling remote attackers to write files or otherwise impact the system; it was added to CISA KEV with a required patch deadline.

If affected, business impact
Remote file write on serversFull system compromise riskService outage and downtimeRansomware path via takeover

What to do now

  1. Check which Bash version your systems run (for example, run: bash --version) and identify whether you’re on an affected version.
  2. If you run an affected vendor/platform, upgrade to the fixed version listed for your platform: Alt Linux SPT → update per vendor instructions; EOS → 4.9.12; QTS → 1.1.1.
  3. If you can’t upgrade immediately, reduce exposure by removing or restricting remote features that pass crafted environment variables across a privilege boundary (for example, avoid allowing remote forced command setups that run under different privileges).
  4. After updating, verify Bash is the updated fixed version and review logs for suspicious file-write or execution attempts around remote access services.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 44 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Jan 28, 2022
Remediation due:Jul 28, 2022

Required action: Apply updates per vendor instructions.

3 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

and 159 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2014-7169 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows