Hackers can exploit a security vulnerability in the Rust standard library to target Windows systems with command injection attacks.
See also: Rust Implant used in new malware campaign against Azerbaijan

Known as CVE-2024-24576, this Rust flaw is due to command injection and operating system definition weaknesses that could allow attackers to execute unexpected and potentially malicious commands on the operating system, such as command injection attacks.
GitHub has rated this vulnerability as critical with a maximum CVSS score of 10/10. Unauthorized attackers can exploit it remotely, in low-sophistication attacks, and without user interaction.
All Rust versions before 1.77.2 on Windows are affected by command injection attacks if a program's code, or one of its dependencies, executes batch files with untrusted arguments.
The Rust security team faced a significant challenge with the complexity of cmd.exe, as they were unable to find a solution that would properly escape requests in all cases.
As a result, they had to improve the robustness of the escape code and modify the Command API. If the Command API cannot safely escape an argument during procedure replication, it returns an InvalidInput error.
See also: RustDoor: New backdoor targets macOS systems

engineer Ryotak, who discovered the vulnerability and named it BatBadBut, says the flaw also affects the following programming languages — however, not all patches have been released:
- Erlang (documentation update)
- Go (documentation update)
- Haskell (patch available)
- Java (no patch available)
- Node.js (patch update will be available)
- PHP (patch will be available)
- Python (documentation update)
- Ruby (documentation update)
In February, the White House Office of the National Director for Cybersecurity (ONCD) urged technology companies to adopt memory-safe programming languages like Rust. The ultimate goal is to improve software security by minimizing the number of memory security vulnerabilities.
See also: RustDoor MacOS Backdoor: Targets Cryptocurrency Companies with Fake Job Opportunities
How can we prevent command injection attacks?
To prevent command injection attacks, such as those enabled by the Rust library flaw, we first need to understand what they are. Command injection attacks are a technique used by attackers to execute commands on a system through a vulnerable application. One of the most effective ways to prevent these attacks is to use input validation. This means that we should always check the data entered by users to ensure that it does not contain malicious code. In addition, we can use the principle of least privilege. This means that we should only give applications the necessary permissions they need to function and no more. Finally, we can use technologies such as Web Application Firewalls (WAFs) and Intrusion Detection Systems (IDSs) to monitor data traffic and detect any abnormal activity.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
