CVE-2024-3566
CRITICALWindows - Command Injection
Title source: llmDescription
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
References (8)
Scores
CVSS v3
9.8
EPSS
0.0709
EPSS Percentile
91.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-77
Status
published
Affected Products (6)
golang/go
haskell/process_library
nodejs/node.js
< 21.7.2
php/php
rust-lang/rust
yt-dlp_project/yt-dlp
Timeline
Published
Apr 10, 2024
Tracked Since
Feb 18, 2026