CyberRota Analysis
AI-GeneratedA local cross-user code execution vulnerability in GNU wget for Windows allows unprivileged users to exploit a hardcoded writable configuration file path (C:\msys64) to execute arbitrary code through the use_askpass directive. This could lead to local privilege escalation, compromising the security of affected systems. Organizations using this version of wget should prioritize remediation to mitigate potential risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execution via the use_askpass directive, potentially allowing local privilege escalation.