#BatBadBut
this is an interesting question. i don't think there's been anything on the scale of log4shell/heartbleed yet, in terms of real world impact. there's been serious vulnerabilities that haven't really been huge impact wise. maybe BatBadBut?
Has there ever been a truly critical memory safety vulnerability in widely used Rust code?

Excluding codegen bugs (like the one in wasmtime), since unfortunately the safety guarantees of Rust only extend to actual rust code, not code generated by rust code.
October 21, 2025 at 5:16 PM
BatBadBut heißt eine kritische Befehlsschmuggel-Lücke, die mehrere Programmiersprachen unter Windows betrifft. Abhilfe ist schwer. #Security
BatBadBut: Kritische Befehlsschmuggel-Lücke in Windows etwa in Rust
BatBadBut heißt eine kritische Befehlsschmuggel-Lücke, die mehrere Programmiersprachen unter Windows betrifft. Abhilfe ist schwer.
www.heise.de
April 10, 2024 at 1:03 PM
🚨 Critical vulnerability alert! 🚨 The "BatBadBut" vulnerability (CVE-2024-24576) in Rust standard library allows arbitrary shell execution on Windows. Update to Rust 1.77.2 now! 🦀 #RustLang #InfoSec
www.cyberkendra.com/2024/04/batb...
"BatBadBut" Vulnerability Discovered in Rust Standard Library on Windows - Cyber Kendra
"BatBadBut" Vulnerability Discovered in Rust Standard Library on Windows
www.cyberkendra.com
April 10, 2024 at 7:45 AM
見てる: "Go, Ruby, Rust等の言語に存在した、Windows環境でコマンドインジェクションを引き起こす脆弱性"BatBadBut" - Flatt Security Blog" https://blog.flatt.tech/entry/batbadbut
June 30, 2024 at 2:03 PM
Rust rustles up fix for 10/10 critical command injection bug on Windows
Rust addresses critical vulnerability on Windows
BatBadBut hits Erlang, Go, Python, Ruby as well
www.theregister.com
April 10, 2024 at 1:27 PM
Just as another heads up, a really good article explaining the problem on the Windows end.

A great bit of research but I think you need to write good input validation to work round this if you choose to build on the platform, imho

flatt.tech/research/pos...
BatBadBut: You can't securely execute commands on Windows
Introduction Hello, I’m RyotaK ( @ryotkak ), a security engineer at Flatt Security Inc. Recently, I reported multiple vulnerabilities to several programming languages that allowed an attacker to perfo...
flatt.tech
April 10, 2024 at 1:25 PM
BatBadBut flaw allowed an attacker to perform command injection on Windows
BatBadBut flaw allowed an attacker to perform command injection on Windows
A critical flaw, named ‘BatBadBut’, impacts multiple programming languages, its exploitation can lead to command injection in Windows apps.
securityaffairs.com
April 13, 2024 at 3:27 PM
Critical 'BatBadBut' Rust Vulnerability Exposes Windows Systems to Attacks
Critical 'BatBadBut' Rust Vulnerability Exposes Windows Systems to Attacks
A severe vulnerability (CVE-2024-24576) in the Rust standard library could lead to command injection attacks on Windows systems.
thehackernews.com
April 10, 2024 at 3:32 AM
CVE-2024-24576、めちゃめちゃ深い話で、Windowsの仕様が根本的にアカンような
flatt.tech/research/pos...
CreateProcess()が使える他言語のライブラリ、全部同じじゃないか疑惑。
BatBadBut: You can't securely execute commands on Windows
Introduction Hello, I’m RyotaK ( @ryotkak ), a security engineer at Flatt Security Inc. Recently, I reported multiple vulnerabilities to several programming languages that allowed an attacker to perfo...
flatt.tech
April 11, 2024 at 12:15 AM
Rust rustles up fix for 10/10 critical command injection bug on Windows
www.theregister.com/2024/04/10/r...
#Infosec #Security #Cybersecurity #CeptBiro #Rust
Rust addresses critical vulnerability on Windows
BatBadBut hits Erlang, Go, Python, Ruby as well
www.theregister.com
April 11, 2024 at 12:35 PM
あ、これ @ryotak.net さんなんだ!

BatBadBut: You can't securely execute commands on Windows - Flatt Security Research flatt.tech/research/pos...
April 13, 2024 at 1:48 PM
<a href="https://blog.flatt.tech/entry/batbadbut" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">blog.flatt.tech/ent...
Go, Ruby, Rust等の言語に存在した、Windows環境でコマンドインジェクションを引き起こす脆弱性"BatBadBut" - Flatt Security Blog
Go, Ruby, Rust等の言語に存在した、Windows環境でコマンドインジェクションを引き起こす脆弱性"BatBadBut" - Flatt Security Blog
※本記事は筆者RyotaKが英語で執筆した記事を、弊社セキュリティエンジニアkoyuriが日本語に翻訳したものになります。 はじめに こんにちは、Flatt SecurityでセキュリティエンジニアをしているRyotaK( @ryotkak )です。 先日、特定の条件を満たした場合に攻撃者がWindows上でコマンドインジェクションを実行できる、いくつかのプログラミング言語に対する複数の脆弱性を報告しました。 本日(2024/04/09(訳者注: これは英語版記事の公開日です))、影響を受けるベンダーがこれらの脆弱性に関するアドバイザリーを公表しました。 その影響は限定的なもののCVSSスコア…
blog.flatt.tech
June 26, 2024 at 2:41 AM
BatBadBut: You can't securely execute commands on Windows
BatBadBut: You can't securely execute commands on Windows
flatt.tech
April 10, 2024 at 12:54 AM
『Flatt SecurityのRyotaK氏が報告したもの』:【セキュリティ ニュース】Windows環境下の複数開発言語に脆弱性「BatBadBut」が判明(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/156020
April 16, 2024 at 1:47 AM
April 10, 2024 at 6:21 AM
BatBadBut: You can't securely execute commands on Windows https://ift.tt/qwI8dVF
January 20, 2025 at 10:30 PM
BatBadBut: You can't securely execute commands on Windows https://ift.tt/qwI8dVF
January 17, 2025 at 1:05 PM