A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
History

Tue, 17 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Golang
Golang go
Haskell
Haskell process Library
Microsoft
Microsoft windows
Nodejs
Nodejs node.js
Php
Php php
Rust-lang
Rust-lang rust
Yt-dlp Project
Yt-dlp Project yt-dlp
Weaknesses CWE-77
CPEs cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:haskell:process_library:1.6.19.0:*:*:*:*:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.77.2:*:*:*:*:*:*:*
cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Golang
Golang go
Haskell
Haskell process Library
Microsoft
Microsoft windows
Nodejs
Nodejs node.js
Php
Php php
Rust-lang
Rust-lang rust
Yt-dlp Project
Yt-dlp Project yt-dlp

Thu, 22 Aug 2024 20:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2024-04-10T15:22:56.099Z

Updated: 2024-08-22T18:25:43.487Z

Reserved: 2024-04-10T04:58:27.982Z

Link: CVE-2024-3566

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.971Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-10T16:15:16.083

Modified: 2025-06-17T20:56:45.503

Link: CVE-2024-3566

cve-icon Redhat

No data.