logo

Critical 'BatBadBut' Rust Vulnerability Exposes Windows Systems to Attacks

ID: 483e2ae3-019a-5d04-b578-022f734b0a8a

STIX ID: report--483e2ae3-019a-5d04-b578-022f734b0a8a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-04-10

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

A critical command injection vulnerability (CVE-2024-24576, "BatBadBut") in the Rust standard library improperly escaped arguments when invoking Windows batch files, allowing an attacker controlling spawn arguments to execute arbitrary shell commands; it affects Rust < 1.77.2, carries a CVSS 10.0 rating, can impact other language runtimes that wrap CreateProcess, and maintainers (including Haskell, Node.js, PHP and yt-dlp) have released patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.