CVE-2024-3566

critical
Published 2024-04-10 · Modified 2026-05-15
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-3566

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Application impact

VendorProductVersionsFixed
haskellprocess_library{"endExcluding":"1.6.19.0"}1.6.19.0
nodejsnode.js{"endExcluding":"18.20.2"}18.20.2
phpphp{"endExcluding":"8.1.28"}8.1.28
rust-langrust{"endExcluding":"1.77.2"}1.77.2
yt-dlp_projectyt-dlp{"startIncluding":"2021.04.11","endExcluding":"2024.04.09"}2024.04.09

References

CWEs

CWE-77

Verify integrity in audit chain (admin only). AS-IS.