HIGH 7.5 Microsoft

CVE-2021-3115

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example cgo can execute a gcc program from an untrusted download).

Microsoft Security Update 2021-Jan: Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example cgo can execute a gcc program from an untrusted download).

Affected Products

References

Published: 2021-01-12 · Source: Microsoft · Feed updated: 2026-09-07
This high severity vulnerability with a CVSS score of 7.5 was published on 2021-01-12 via Microsoft. EPSS score: 6.5% (top 7% of all CVEs by exploitation probability). Affected: azl3 python-tensorboard 2.16.2-1 on Azure Linux 3.0, azl3 python-tensorboard 2.11.0-3 on Azure Linux 3.0.
vulnfeed aggregates 10539 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.