EXPOSURES › CVE-2014-7169
CVE-2014-7169
HIGH ⌖ ON CISA KEV · EXPLOITEDA remote code execution flaw in GNU Bash allowed attackers to execute arbitrary code via environment variables, a known vulnerability that remains actively exploited in the wild.
GNU Bash through 4.3 processes trailing strings after function definitions in environment variables, enabling remote attackers to execute code. Defense-industrial-base organizations must care because this is a foundational system component with a history of critical RCE flaws, requiring strict version control and urgent patching to prevent compromise. The vulnerability is listed in CISA's KEV catalog, indicating it is actively exploited in the wild, making it a high-priority remediation target.
Shame score — A foundational system like Bash has a critical, actively exploited RCE flaw that persists across multiple versions, reflecting a severe failure in patching and version management that directly enables remote compromise.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.