CVE-2024-43402 is a critical vulnerability affecting Rust versions prior to 1.81.0, specifically impacting the std::process::Command function on Windows when invoking batch files. This flaw allows for a bypass of a previous fix (CVE-2024-24576) by exploiting how Windows handles trailing whitespace or periods in batch file names, leading to incorrect argument escaping. With a CVSS score of 8.8 (HIGH), it presents a significant risk (FAUCET Risk Score 70/100) due to potential command injection (CWE-78, CWE-88) with high confidentiality, integrity, and availability impacts, requiring only low privileges and local access. Currently, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion, but users are advised to update to Rust 1.81.0 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.81.0CPE matchmatch criteria | cpe:2.3:a:rust-lang:rust:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.