PT-2024-5911 · Rust+1 · Rust+1

4Xpl0R3R

·

Published

2024-04-09

·

Updated

2025-07-19

·

CVE-2024-43402

CVSS v3.1

8.1

High

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rust (affected versions not specified)
Description The issue is related to the std::process::Command component of the Rust programming language on Windows operating systems. It involves the injection or modification of arguments, potentially allowing an attacker to execute arbitrary code by calling user batch files with .bat and .cmd extensions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Argument Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15409
ALT-PU-2024-15614
BDU:2024-06717
CVE-2024-43402
GHSA-2XG3-7MM6-98JJ

Affected Products

Alt Linux
Rust