IT

Tracker / CVE-2024-3566

CVE-2024-3566

Critical 9.8

A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.

Affected products and versions

haskell process_library · … → 1.6.19.0
nodejs node.js · … → 18.20.2
nodejs node.js · 19.0.0 → 20.12.2
nodejs node.js · 21.0.0 → 21.7.3
php php · … → 8.1.28
php php · 8.2.0 → 8.2.18
php php · 8.3.0 → 8.3.6
rust-lang rust · … → 1.77.2
yt-dlp_project yt-dlp · 2021.04.11 → 2024.04.09

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References