← Back

CVE-2024-3566

nvd nist
Published: Apr 10, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

Affected (9)

Products: Haskell: Process Library · Nodejs: Node.js · Php: Php · +2 more
Show all products
1 product
Process Library
1 product
Node.js
1 product
Php
1 product
Rust
Yt Dlp
Configuration A
9 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.6.19.0
Nodejs
Before 18.20.2
From 19.0.0 to 20.12.2
From 21.0.0 to 21.7.3
Php
Before 8.1.28
From 8.2.0 to 8.2.18
From 8.3.0 to 8.3.6
Before 1.77.2
From 2021.04.11 to 2024.04.09
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (15)

Source: cret@cert.org
Third Party Advisory
Source: cret@cert.org
Not Applicable
Source: cret@cert.org
Not Applicable
Source: cret@cert.org
Not Applicable
Source: cret@cert.org
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable

Timeline

No history available yet.