CVE-2024-3566

CWE-77Command Injection5 documents5 sources
Severity
9.8CRITICAL
EPSS
7.1%
top 8.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateNov 14

Description

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages7 packages

Hackageprocess1.0.0.01.6.23.0
NVDnodejs/node.js21.7.2
CVEListV5node.js/node.js*21.7.2
NVDrust-lang/rust1.77.2

🔴Vulnerability Details

3
OSV
process: command injection via argument list on Windows2025-11-14
CVEList
Command injection vulnerability in programing languages on Microsoft Windows operating system.2024-04-10
GHSA
GHSA-9xch-xvj3-fmf3: A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess fun2024-04-10

📋Vendor Advisories

1
Debian
CVE-2024-3566: nodejs - A command inject vulnerability allows an attacker to perform command injection o...2024
CVE-2024-3566 (CRITICAL CVSS 9.8) | A command inject vulnerability allo | cvebase.io