NSA’s reverse engineering tool Ghidra impacted by a bug — but there's no need to panic
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-16941 | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call). NVD description · AI analysis pending | 9.8 | 5% | PoC |
| — |
Full article755 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
There is a vulnerability in the NSA's reverse engineering tool. But it would take an incredible scenario for it impact anyone.
The National Security Agency’s open source reverse engineering tool, Ghidra, is impacted by a vulnerability, but security experts — including those at the NSA familiar with Ghidra — tell CyberScoop it would be pretty difficult to be attacked via the vulnerability if you know how to reverse engineer malware.
The vulnerability, CVE-2019-16941, would allow hackers to compromise exposed systems when Ghidra’s experimental mode is running, according to the bug announcement from the National Institute of Standards and Technology. In theory, this vulnerability would allow arbitrary code to be executed against a Ghidra user if a malicious XML document — a plain text file often used to store data — is introduced. But that introduction is unlikely to happen because running these kinds of files through Ghidra would be pretty unusual, researchers told CyberScoop.
“These files are not normally shared among users and not normally part of the distribution,” the NSA researchers said.
Although the posting on Ghidra’s GitHub page suggests remote code execution is a concern as a result of this vulnerability, NSA researchers said that the bug would not allow remote access unless one Ghidra user — who is using both Ghidra’s experimental mode and the Bit Patterns Explorer, a Ghidra plugin — accepts a maliciously modified file from yet another Ghidra user who is also using that plugin.
“I don’t think anybody [that’s a] reverse engineer is going to accept a random XML file from a stranger and load it into Ghidra,” Dragos Senior Adversary Hunter Jimmy Wylie told CyberScoop.
The NSA said it became aware of the bug after it was submitted to GitHub on Saturday. The agency is working on a remedy that it will issue along with a new version of Ghidra after its beta testing period is over. This fix will come along with several other features meant to boost accuracy and save time in reverse-engineering, according to the agency.
In the meantime, the NSA says there is an easy fix in the short-term for this bug.
“You can mitigate risk by not accepting XML files from sources that you don’t trust,” a spokesperson told CyberScoop.
More Scoops
Where’s the Trump administration line on AI regulation?
The messy approach to U.S. AI regulation reflects both the rapid speed of model cyber capabilities and the White House’s “education” over the past two years, experts…
Chinese researchers accuse NSA of being behind a powerful exploit
NSA, FBI publicize hacking tool linked to Russian military intelligence
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ghidra-vulnerability-nsa-reverse-engineering/