CVE-2024-24576 affects the Rust standard library prior to Rust 1.77.2 on Windows. When std::process::Command is used to invoke batch files with .bat or .cmd extensions, the library's argument escaping logic is insufficient for cmd.exe parsing semantics. Although Command::arg and Command::args are documented to pass arguments as-is without shell evaluation, Windows batch-file execution is a special case because the Windows process creation API passes a single command-line string and cmd.exe applies its own argument splitting and interpretation rules. The Rust standard library implemented custom escaping for this case, but the escaping was incomplete, allowing attacker-controlled arguments to break out of the intended argument context and trigger arbitrary shell command execution. The issue is limited to Windows batch-file execution paths and does not affect other platforms or non-batch invocations in the described advisory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
.bat or .cmd process can achieve arbitrary command execution on the affected Windows system in the security context of the vulnerable Rust application. Depending on that process's privileges, this can lead to full compromise of the host, unauthorized actions, data access, persistence, or lateral movement. The issue is described as critical for applications that invoke batch files on Windows with untrusted input.If you can’t patch tonight, do this now.
.bat or .cmd files from Rust applications on Windows with untrusted or user-controlled arguments. Prefer executing non-shell binaries directly where possible. If batch-file execution is unavoidable, strictly validate, constrain, or neutralize user-supplied input before passing it as an argument. Reduce exposure by ensuring only trusted data reaches Command::arg/Command::args for batch invocations and by running the vulnerable application with the least privileges necessary.Patch, then assume compromise.
Command API behavior to return an InvalidInput error when an argument cannot be safely escaped. Review code paths that use std::process::Command to launch .bat or .cmd files on Windows, especially where untrusted input is passed via Command::arg or Command::args. If applications intentionally rely on custom escaping or only use trusted inputs, Rust provides CommandExt::raw_arg to bypass the standard library escaping logic, but this should only be used with extreme care.4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-24576, a command injection vulnerability affecting Rust's std::process::Command on Windows. The exploit is implemented in Julia (main.jl), which prompts the user for input, then passes that input as an argument to a batch file (test.bat) using Julia's Cmd and run functions. If the input contains command separators (such as '&'), arbitrary commands can be executed on the system, demonstrating the vulnerability. The batch file simply echoes the received argument, but due to improper escaping, additional commands can be injected. The repository includes a readme.md with usage examples and references to the original advisories. The exploit is local (requires user interaction or local access), and the main fingerprintable endpoint is the test.bat file invoked by main.jl. The code is a minimal PoC and does not include weaponized or automated exploitation features.
This repository demonstrates a proof-of-concept exploit for CVE-2024-24576, a command injection vulnerability in Rust's std::process::Command API on Windows when invoking batch files. The repository contains three main exploit scripts in Go (main.go), Python (main.py), and Rust (main.rs), each of which executes a batch file (test.bat) with user-supplied arguments. The exploit leverages improper argument escaping, allowing an attacker to inject arbitrary shell commands (e.g., 'test && whoami') via the command line arguments. The batch file simply echoes its arguments, serving as a placeholder for demonstrating the injection. The exploit is local and requires the attacker to supply malicious input to a vulnerable Rust application. The repository is structured as a multi-language POC, with each script illustrating the vulnerability in a different language context, but all targeting the same underlying issue in the Rust standard library on Windows.
This repository is a proof-of-concept (PoC) exploit for CVE-2024-24576, a command injection vulnerability in Rust's std::process::Command API on Windows. The vulnerability arises from improper escaping of arguments when passing user input to batch files (cmd.exe), allowing attackers to inject arbitrary shell commands. The repository contains three files: a README.md explaining the vulnerability and usage, a Rust source file (main.rs) that reads user input and passes it as an argument to a batch file, and a simple batch file (test.bat) that echoes the received argument. The PoC demonstrates how specially crafted input can break out of the intended argument context and execute additional commands. The exploit is local, requiring the attacker to supply input to a vulnerable Rust application on Windows. No network endpoints are involved, but the batch file path (./test.bat) is fingerprintable. The code is a clear and concise demonstration of the vulnerability, suitable for testing and research purposes.
This repository provides a proof-of-concept (POC) for CVE-2024-24576, a vulnerability in how Windows handles arguments passed to batch files, potentially allowing for command injection. The repository contains three main exploit scripts in Go (24576.go), Python (24576.py), and Ruby (24576.rb), each prompting the user for input and passing it as an argument to a batch file (test.bat). The batch file simply echoes the received argument, but the exploit demonstrates that by crafting the input (e.g., including a double quote), an attacker can escape the intended argument context and execute arbitrary commands (such as launching calc.exe). The README provides context, references, and credits, and notes that the Ruby version appears unaffected by the exploit path. The attack vector is local, requiring the user to run the script and provide malicious input. The main fingerprintable endpoint is the batch file path used in each script. The repository is structured as a multi-language POC for demonstrating the vulnerability, not as a weaponized exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.