logo

Rust rustles up fix for 10/10 critical command injection bug on Windows in std lib

ID: 8bfa3ee4-a9e8-5fda-95e7-d625aca2b3e3

STIX ID: report--8bfa3ee4-a9e8-5fda-95e7-d625aca2b3e3

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-04-10

Date Updated: 2026-04-26

Author: Connor Jones

...
...

CVE-2024-24576 (dubbed "BatBadBut") is a critical vulnerability in Rust's std::process::Command where improper escaping of arguments when spawning batch files on Windows can allow attacker-controlled inputs to result in arbitrary CMD.exe shell execution; Rust 1.77.2 patches the issue, other languages and runtimes are also affected or updating guidance, and developers are urged to update or apply mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.