yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-3566
Component Overview
Vulnerability Overview
Name
CVE-2024-3566
Source
NVD (
link
)
Debian (
link
)
Description
A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
CWEs
CWE-77
Published Date
Apr 10, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/
Exploit
https://kb.cert.org/vuls/id/123335
Third Party Advisory
https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/everyone-quotes-command-line-arguments-the-wrong-way
Technical Description
https://www.cve.org/CVERecord?id=CVE-2024-1874
Not Applicable
https://www.cve.org/CVERecord?id=CVE-2024-22423
Not Applicable
https://www.cve.org/CVERecord?id=CVE-2024-24576
Not Applicable
https://www.kb.cert.org/vuls/id/123335
Not Applicable
https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/
Exploit
https://github.com/nu11secur1ty/Windows11Exploits/tree/main/2024/CVE-2024-3566
Third Party Advisory
https://kb.cert.org/vuls/id/123335
Third Party Advisory
https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/everyone-quotes-command-line-arguments-the-wrong-way
Technical Description
https://www.cve.org/CVERecord?id=CVE-2024-1874
Not Applicable
https://www.cve.org/CVERecord?id=CVE-2024-22423
Not Applicable
https://www.cve.org/CVERecord?id=CVE-2024-24576
Not Applicable
https://www.kb.cert.org/vuls/id/123335
Not Applicable
Analysis
#
Affected Component
Analysis
go
False Positive
go-binary-native
False Positive
php
False Positive
nodejs
False Positive
Vulnerability Ratings
#
9.8
CVSSv31
9.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
nodejs-src
buildroot
2025.02.x
22.22.0
Not Affected
php
buildroot
2025.02.x
8.3.31
Not Affected
nodejs-src
buildroot
master
22.22.0
Not Affected
php
buildroot
master
8.5.7
Not Affected
golang-bootstrap
openwrt
master
1.24.13-r1
Not Affected
golang1.26
openwrt
master
1.26.4-r1
Not Affected
node
openwrt
master
22.23.0-r1
Not Affected
php8
openwrt
master
8.4.16-r4
Not Affected
golang-bootstrap
openwrt
openwrt-25.12
1.24.13-r1
Not Affected
golang1.26
openwrt
openwrt-25.12
1.26.4-r1
Not Affected
node
openwrt
openwrt-25.12
22.23.0-r1
Not Affected
php8
openwrt
openwrt-25.12
8.4.21-r1
Not Affected
go
yocto
kirkstone
1.17.13
Not Affected
go-binary-native
yocto
kirkstone
1.17.13
Not Affected
nodejs
yocto
kirkstone
16.20.2
Not Affected
php
yocto
kirkstone
8.1.34
Not Affected
go
yocto
master
1.26.4
False Positive
go-binary-native
yocto
master
1.26.4
False Positive
nodejs
yocto
master
24.17.0
Not Affected
php
yocto
master
8.5.7
False Positive