Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-24576-PoC-BatBadBut — PoC for CVE-2024-24576 vulnerability "BatBadBut" | Kitploit
Tools/GitHubGitHub/shel3g/cve-2024-24576-poc-batbadbut
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubshel3g/cve-2024-24576-poc-batbadbut

CVE-2024-24576-PoC-BatBadBut

PoC for CVE-2024-24576 vulnerability "BatBadBut"

View Repository
22 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-24576-PoC-BatBadBut

PoC for CVE-2024-24576 vulnerability "BatBadBut"

Information

After running the script will ask you for an argument, the argument will be passed the the bat file, if you close the argument with " and after that & you can run any Windows command. For example:

helloworld" & whoami

As a result, you will get the whoami command.

Of course in real time it would not look like that, this is just PoC for the CVE.

Usage

Clone the repository:

git clone https://github.com/SheL3G/CVE-2024-24576-PoC-BatBadBut.git

Running the script:

Python CVE-2024-24576.py

To make it work type something close with " and then "&" and any command like calc.exe, hostname, whoami...

HelloWorld" & hostname

The Flow of the CVE and the possible way to make it work Flow

Credits

  • NIST

  • flatt.tech

  • Mental Outlow

License

MIT

Download Tool