Critical 'BatBadBut' Rust Vulnerability Exposes Windows Systems to Attacks
ID: 483e2ae3-019a-5d04-b578-022f734b0a8a
STIX ID: report--483e2ae3-019a-5d04-b578-022f734b0a8a
Feed Name: The Hacker News
Threat Score
A critical command injection vulnerability (CVE-2024-24576, "BatBadBut") in the Rust standard library improperly escaped arguments when invoking Windows batch files, allowing an attacker controlling spawn arguments to execute arbitrary shell commands; it affects Rust < 1.77.2, carries a CVSS 10.0 rating, can impact other language runtimes that wrap CreateProcess, and maintainers (including Haskell, Node.js, PHP and yt-dlp) have released patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
