Impact
Hashcat does not validate command‑line options when reading restore files, allowing an attacker to inject output‑redirecting options such as --outfile and --potfile-path. By crafting a malicious restore file, an attacker can cause hashcat to append attacker‑controlled data to arbitrary files. If the target system processes those files—such as shell startup files—this can lead to remote or local code execution.
Affected Systems
The vulnerability affects the hashcat password‑cracking tool up to and including version 7.1.2. Users of hashcat 7.1.2 or earlier are impacted.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and no EPSS score is available; we have no data on exploitation probability. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. The attack requires an attacker to supply a crafted restore file to hashcat; this is typically a local attack scenario, but could be leveraged in environments where hashcat runs with elevated privileges or processes user‑supplied restore files.
OpenCVE Enrichment