ZeroHour
CyberScooppublished ()ingested @shanvav

NSA’s reverse engineering tool Ghidra impacted by a bug — but there's no need to panic

criticalExploit / PoC exploited in the wildimportance 60CVE-2019-16941

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-16941
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with

NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Explorer is used with a modified XML document. This occurs in Features/BytePatterns/src/main/java/ghidra/bitpatterns/info/FileBitPatternInfoReader.java. An attack could start with an XML document that was originally created by DumpFunctionPatternInfoScript but then directly modified by an attacker (for example, to make a java.lang.Runtime.exec call).

NVD description · AI analysis pending
9.85% PoC
  • nsa ghidra
Full article755 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

There is a vulnerability in the NSA's reverse engineering tool. But it would take an incredible scenario for it impact anyone.

NSA, National Security Agency, RSA 2019, china nsa hacking tools, NSA cybersecurity directorate, ghidra vulnerability
(Scoop News Group photo)

The National Security Agency’s open source reverse engineering tool, Ghidra, is impacted by a vulnerability, but security experts — including those at the NSA familiar with Ghidra — tell CyberScoop it would be pretty difficult to be attacked via the vulnerability if you know how to reverse engineer malware.

The vulnerability, CVE-2019-16941, would allow hackers to compromise exposed systems when Ghidra’s experimental mode is running, according to the bug announcement from the National Institute of Standards and Technology. In theory, this vulnerability would allow arbitrary code to be executed against a Ghidra user if a malicious XML document — a plain text file often used to store data — is introduced. But that introduction is unlikely to happen because running these kinds of files through Ghidra would be pretty unusual, researchers told CyberScoop.

“These files are not normally shared among users and not normally part of the distribution,” the NSA researchers said.

Although the posting on Ghidra’s GitHub page suggests remote code execution is a concern as a result of this vulnerability, NSA researchers said that the bug would not allow remote access unless one Ghidra user — who is using both Ghidra’s experimental mode and the Bit Patterns Explorer, a Ghidra plugin — accepts a maliciously modified file from yet another Ghidra user who is also using that plugin.

“I don’t think anybody [that’s a] reverse engineer is going to accept a random XML file from a stranger and load it into Ghidra,” Dragos Senior Adversary Hunter Jimmy Wylie told CyberScoop.

The NSA said it became aware of the bug after it was submitted to GitHub on Saturday. The agency is working on a remedy that it will issue along with a new version of Ghidra after its beta testing period is over. This fix will come along with several other features meant to boost accuracy and save time in reverse-engineering, according to the agency.

In the meantime, the NSA says there is an easy fix in the short-term for this bug.

“You can mitigate risk by not accepting XML files from sources that you don’t trust,” a spokesperson told CyberScoop.

More Scoops

US President Donald Trump (R) and Open AI CEO Sam Altman (L) react during a working lunch meeting of G7 members, partner countries, and artificial intelligence business leaders as part of the G7 summit, in Evian, eastern France, on June 17, 2026. The Trump administration has been moving to regulate AI models for cybersecurity use. (Photo by Julia Demaree Nikhinson / POOL / AFP via Getty Images)

Where’s the Trump administration line on AI regulation?

The messy approach to U.S. AI regulation reflects both the rapid speed of model cyber capabilities and the White House’s “education” over the past two years, experts…

A sign for the National Security Agency (NSA), U.S. Cyber Command and Central Security Service, is seen near the visitor’s entrance to the headquarters of the NSA at the entrance in Fort Meade, Maryland, February 14, 2018. (Photo by SAUL LOEB/AFP via Getty Images)

Chinese researchers accuse NSA of being behind a powerful exploit

(Getty images)

NSA, FBI publicize hacking tool linked to Russian military intelligence

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ghidra-vulnerability-nsa-reverse-engineering/