{"cveID":"CVE-2014-7169","vendorProject":"GNU","product":"Bourne-Again Shell (Bash)","vulnerabilityName":"GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability","dateAdded":"2022-01-28","shortDescription":"GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-07-28","knownRansomwareCampaignUse":"Unknown","notes":"https://nvd.nist.gov/vuln/detail/CVE-2014-7169","cwes":["CWE-78"],"year":2014,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2014-7169","technique":"T1133","technique_name_at_mapping":"External Remote Services","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"CVE-2014-7169 allows environment variables set from service/HTTP requests on a serve (e.g. HTTP_COOKIE) in Bash shell that allows for spawning a child shell with the authority/privilege level of the parent shell to perform RCE of code provided by the adversary in the request. ","references":["http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2014-7169","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"code_execution","comments":"CVE-2014-7169 allows environment variables set from service/HTTP requests on a serve (e.g. HTTP_COOKIE) in Bash shell that allows for spawning a child shell with the authority/privilege level of the parent shell to perform RCE of code provided by the adversary in the request. ","references":["http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2014-7169","technique":"T1059.004","technique_name_at_mapping":"Unix Shell","mapping_type":"primary_impact","capability_group":"code_execution","comments":"CVE-2014-7169 allows environment variables set from service/HTTP requests on a serve (e.g. HTTP_COOKIE) in Bash shell that allows for spawning a child shell with the authority/privilege level of the parent shell to perform RCE of code provided by the adversary in the request. ","references":["http://lcamtuf.blogspot.com/2014/09/quick-notes-about-bash-bug-its-impact.html"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1059.004","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Unix Shell","name_at_mapping":"Unix Shell","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":18,"has_detection_strategy":true},{"id":"T1133","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"External Remote Services","name_at_mapping":"External Remote Services","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":20,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-23 05:47 UTC","_attack_version":"19.2"}