Vulnerability Description
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Haskell | Process Library | < 1.6.19.0 |
| Nodejs | Node.Js | < 18.20.2 |
| Php | Php | < 8.1.28 |
| Rust-Lang | Rust | < 1.77.2 |
| Yt-Dlp Project | Yt-Dlp | >= 2021.04.11, < 2024.04.09 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-oExploitThird Party Advisory
- https://kb.cert.org/vuls/id/123335Third Party Advisory
- https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/eveTechnical Description
- https://www.cve.org/CVERecord?id=CVE-2024-1874Not Applicable
- https://www.cve.org/CVERecord?id=CVE-2024-22423Not Applicable
- https://www.cve.org/CVERecord?id=CVE-2024-24576Not Applicable
- https://www.kb.cert.org/vuls/id/123335Not Applicable
- https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-oExploitThird Party Advisory
- https://github.com/nu11secur1ty/Windows11Exploits/tree/main/2024/CVE-2024-3566Third Party Advisory
- https://kb.cert.org/vuls/id/123335Third Party Advisory
- https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/eveTechnical Description
- https://www.cve.org/CVERecord?id=CVE-2024-1874Not Applicable
- https://www.cve.org/CVERecord?id=CVE-2024-22423Not Applicable
- https://www.cve.org/CVERecord?id=CVE-2024-24576Not Applicable
- https://www.kb.cert.org/vuls/id/123335Not Applicable
FAQ
What is CVE-2024-3566?
CVE-2024-3566 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
How severe is CVE-2024-3566?
CVE-2024-3566 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-3566?
Check the references section above for vendor advisories and patch information. Affected products include: Haskell Process Library, Nodejs Node.Js, Php Php, Rust-Lang Rust, Yt-Dlp Project Yt-Dlp.