CERT/CC published advisory VU#123335 for BatBadBut, a Windows command injection vulnerability class affecting multiple programming language runtimes that improperly escape arguments when launching commands. The issue stems from Microsoft Windows behavior in which CreateProcess can implicitly invoke cmd.exe for batch files such as .bat and .cmd, causing arguments escaped for normal process creation to be reinterpreted under cmd.exe parsing rules. Under those conditions, user-controlled input passed to a batch-file command can trigger command injection.
Research from GMO Flatt Security said exposure is broader than explicit batch-file execution because Windows PATHEXT can cause a program call without an extension to resolve to a batch file instead of an executable. The report added that simple quote escaping is insufficient because cmd.exe performs additional parsing and variable expansion, including %CMDCMDLINE%, before later processing stages. Affected ecosystems include multiple language runtimes, with some vendors issuing patches while others provided documentation updates or declined fixes, leaving developers to avoid batch-file invocation paths and review Windows command execution that includes untrusted arguments.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CERT/CC published vulnerability note VU#123335 covering multiple programming languages that fail to escape arguments properly on Microsoft Windows. The note documents the cross-language nature of the issue highlighted by BatBadBut.
Affected vendors published advisories on April 9, 2024, in response to BatBadBut. According to the research, Haskell, Node.js, PHP, and Rust had patches available; Erlang, Go, Python, and Ruby issued documentation updates; and Java was listed as "Won’t fix."
Flatt Security published research on the BatBadBut vulnerability class, describing how Windows batch-file execution via CreateProcess and cmd.exe parsing differences can enable command injection in affected applications and runtimes. The research states that RyotaK reported related issues to multiple programming language vendors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.