HomeSecurityCritical Rust bug allows command injection attacks

Critical Rust bug allows command injection attacks

Hackers can exploit a security vulnerability in the Rust standard library to target Windows systems with command injection attacks.

See also: Rust Implant used in new malware campaign against Azerbaijan

Rust command injection

Known as CVE-2024-24576, this Rust flaw is due to command injection and operating system definition weaknesses that could allow attackers to execute unexpected and potentially malicious commands on the operating system, such as command injection attacks.

GitHub has rated this vulnerability as critical with a maximum CVSS score of 10/10. Unauthorized attackers can exploit it remotely, in low-sophistication attacks, and without user interaction.

All Rust versions before 1.77.2 on Windows are affected by command injection attacks if a program's code, or one of its dependencies, executes batch files with untrusted arguments.

The Rust security team faced a significant challenge with the complexity of cmd.exe, as they were unable to find a solution that would properly escape requests in all cases.

As a result, they had to improve the robustness of the escape code and modify the Command API. If the Command API cannot safely escape an argument during procedure replication, it returns an InvalidInput error.

See also: RustDoor: New backdoor targets macOS systems

Critical Rust bug allows command injection attacks

engineer Ryotak, who discovered the vulnerability and named it BatBadBut, says the flaw also affects the following programming languages ​​— however, not all patches have been released:

  • Erlang (documentation update)
  • Go (documentation update)
  • Haskell (patch available)
  • Java (no patch available)
  • Node.js (patch update will be available)
  • PHP (patch will be available)
  • Python (documentation update)
  • Ruby (documentation update)

In February, the White House Office of the National Director for Cybersecurity (ONCD) urged technology companies to adopt memory-safe programming languages ​​like Rust. The ultimate goal is to improve software security by minimizing the number of memory security vulnerabilities.

See also: RustDoor MacOS Backdoor: Targets Cryptocurrency Companies with Fake Job Opportunities

How can we prevent command injection attacks?

To prevent command injection attacks, such as those enabled by the Rust library flaw, we first need to understand what they are. Command injection attacks are a technique used by attackers to execute commands on a system through a vulnerable application. One of the most effective ways to prevent these attacks is to use input validation. This means that we should always check the data entered by users to ensure that it does not contain malicious code. In addition, we can use the principle of least privilege. This means that we should only give applications the necessary permissions they need to function and no more. Finally, we can use technologies such as Web Application Firewalls (WAFs) and Intrusion Detection Systems (IDSs) to monitor data traffic and detect any abnormal activity.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS