CVE-2024-36138
Last modified
CVE-2024-36138 is a vulnerability of currently unknown severity. Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.. EPSS estimates a 1.10% chance of exploitation in the next 30 days.
Description
Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-36138?
How severe is CVE-2024-36138?
How do I fix CVE-2024-36138?
Are you affected by CVE-2024-36138?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
