A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
2024-04-10T16:15:16.083
2025-06-25T20:24:12.743
Analyzed
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | golang | go | * | Yes |
Application | haskell | process_library | 1.6.19.0 | Yes |
Application | nodejs | node.js | ≤ 21.7.2 | Yes |
Application | php | php | * | Yes |
Application | rust-lang | rust | 1.77.2 | Yes |
Application | yt-dlp_project | yt-dlp | * | Yes |
Operating System | microsoft | windows | - | No |