VDB
GSD-2024-3566
GSD-2024-3566
PUBLISHED
CVSS 9.800000190734863 CRITICAL
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haskell Programming Language | Haskel | * |
| rust-lang | rust | 0 |
| nodejs | nodejs | 0 |
| thephpgroup | thephpgroup | 0 |
| Node.js | Node.js | * |
| Go Programming Language | GoLang | * |
| yt-dlp_project | yt-dlp | 0 |
| haskell | process_library | 0 |
Timeline
- Apr 10, 2024 CVE Published
- Feb 10, 2026 PoC Published
- Apr 3, 2026 Security Advisory
- Apr 3, 2026 Security Advisory
References
- https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/ url
- https://www.cve.org/CVERecord?id=CVE-2024-24576 url
- https://www.cve.org/CVERecord?id=CVE-2024-1874 url
- https://www.cve.org/CVERecord?id=CVE-2024-22423 url
- https://kb.cert.org/vuls/id/123335 advisory
- https://github.com/nu11secur1ty/Windows11Exploits/tree/main/2024/CVE-2024-3566 exploit
- https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/everyone-quotes-command-line-arguments-the-wrong-way advisory
- https://www.kb.cert.org/vuls/id/123335 advisory