CVE-2024-3566

CRITICAL

Windows - Command Injection

Title source: llm

Description

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

Scores

CVSS v3 9.8
EPSS 0.0709
EPSS Percentile 91.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-77
Status published

Affected Products (6)

golang/go
haskell/process_library
nodejs/node.js < 21.7.2
php/php
rust-lang/rust
yt-dlp_project/yt-dlp

Timeline

Published Apr 10, 2024
Tracked Since Feb 18, 2026