CVE-2024-3566
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
Affected (9)
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.6.19.0 | |
| Before 18.20.2 | |
| Before 8.1.28 | |
| Before 1.77.2 | |
| From 2021.04.11 to 2024.04.09 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (15)
Source: cret@cert.org
ExploitThird Party Advisory
Source: cret@cert.org
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Source: af854a3a-2127-422b-91ae-364da2661108
Not Applicable
Timeline
No history available yet.