PT-2024-26606 · Microsoft+1 · Windows+1

Ryotak

·

Published

2024-04-09

·

Updated

2026-05-15

·

CVE-2024-3566

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions process versions prior to 1.6.19.0 GHC versions prior to 9.10.1-alpha3 GHC versions prior to 9.8.3 GHC versions prior to 9.6.5 Node.js versions up to 21.7.2
Description A command injection vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when specific conditions are satisfied. The issue arises when executing .bat or .cmd files, and the argument values include or are influenced by program input. This vulnerability was discovered in many programming languages' Windows process execution behavior. The estimated number of potentially affected devices is not specified.
Recommendations For process versions prior to 1.6.19.0, update to version 1.6.19.0 or later. For GHC versions prior to 9.10.1-alpha3, update to version 9.10.1-alpha3 or later. For GHC versions prior to 9.8.3, update to version 9.8.3 or later. For GHC versions prior to 9.6.5, update to version 9.6.5 or later. For Node.js versions up to 21.7.2, no fix is available yet, consider avoiding execution of batch files where arguments include or are influenced by untrusted program inputs, and reject arguments that include special characters including & and " as a temporary workaround.

Exploit

Fix

DoS

Command Injection

Weakness Enumeration

Related Identifiers

ALSA-2025_15900
ALSA-2025_15904
ALSA-2025_19927
ALSA-2025_20909
ALSA-2025_20957
ALSA-2025_21232
ALSA-2025_21702
ALSA-2025_21815
ALSA-2025_22011
ALSA-2025_22668
ALSA-2025_23087
ALSA-2025_23325
ALSA-2025_23326
ALSA-2025_23543
ALSA-2025_23948
ALT-PU-2025-12699
ALT-PU-2025-13032
ALT-PU-2025-13232
BIT-NODE-2024-3566
BIT-NODE-MIN-2024-3566
CVE-2024-3566
HSEC-2024-0003

Affected Products

Alt Linux
Windows