logo

Critical Rust flaw enables Windows command injection attacks

ID: f7065e83-0e0a-5fc5-892d-948e63a291e3

STIX ID: report--f7065e83-0e0a-5fc5-892d-948e63a291e3

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-04-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**Executive summary:** The report describes CVE-2024-24576, a critical command- and argument-injection flaw in the Rust standard library that can allow unauthenticated remote execution when programs spawn Windows batch files with untrusted arguments; affected Rust versions prior to 1.77.2 on Windows should be updated and mitigations applied, and several other languages/documentation were noted as impacted or updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.