QID 379598
Date Published: 2024-04-10
QID 379598: Rust Standard Library Remote Code Execution (RCE) Vulnerability (BatBadBut)
Rust is a programming language.
The Rust standard library fails to properly escape arguments passed to batch files on Microsoft Windows when using the Command API. An attacker could exploit this vulnerability by passing malicious arguments, resulting in arbitrary shell execution.
Affected Versions:
Rust versions before 1.77.2 on Windows
QID Detection Logic:
This authenticated QID
Successful exploitation allows an attacker to execute arbitrary code on a targeted system.
Solution
Customers are advised to upgrade to Rust 1.77.2 or later versions to remediate this vulnerability.
Vendor References
- CVE-2024-24576 -
blog.rust-lang.org/2024/04/09/cve-2024-24576.html
CVEs related to QID 379598
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Rust 1.77.2 or later |
|