CVE-2024-3566
Severity
9.8CRITICAL
EPSS
7.1%
top 8.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 10
Latest updateNov 14
Description
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages7 packages
🔴Vulnerability Details
3CVEList▶
Command injection vulnerability in programing languages on Microsoft Windows operating system.↗2024-04-10
GHSA▶
GHSA-9xch-xvj3-fmf3: A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess fun↗2024-04-10
📋Vendor Advisories
1Debian▶
CVE-2024-3566: nodejs - A command inject vulnerability allows an attacker to perform command injection o...↗2024