CyberzSOC

Publication detail
← Back to advisories & guidance

2024-035: Critical Vulnerability in Rust on Windows ↗ source

April 10, 2024 CERT-EU Advisory

Summary

This flaw allows command injection attacks via crafted batch file executions with untrusted arguments. It is recommended updating as soon as possible, prioritising assets running code (or one of its dependencies) which executes batch files with untrusted arguments [1]. The vulnerability, identified as CVE-2024-24576 with a CVSS score of 10, stems from improper sanitisation of command-line arguments which could be manipulated to execute arbitrary commands. This issue affects all Rust versions prior to 1.77.2 on Windows if a program’s code or one of its dependencies invokes and executes batch files with untrusted arguments [1]. All Rust versions before 1.77.2 on Windows are affected [2].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-24576 10.0 Critical rust-lang rust Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly es…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.