CVE-2024-3566

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
10/04/2024
Last modified:
25/06/2025

Description

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:haskell:process_library:1.6.19.0:*:*:*:*:*:*:*
cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* 21.7.2 (including)
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:rust-lang:rust:1.77.2:*:*:*:*:*:*:*
cpe:2.3:a:yt-dlp_project:yt-dlp:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*