PT-2023-2909 · Vm2 · Vm2

·

CVE-2023-32314

·

Published

2023-05-15

·

Updated

2026-07-21

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions vm2 versions up to and including 3.9.17
Description A sandbox escape issue exists in vm2, allowing a threat actor to bypass sandbox protections and gain remote code execution rights on the host. This is achieved by abusing an unexpected creation of a host object based on the specification of Proxy. The vulnerability can be exploited by a remote attacker to execute arbitrary code.
Recommendations For versions up to and including 3.9.17, upgrade to version 3.9.18 or later to patch the vulnerability. As a temporary workaround, consider restricting access to the Proxy specification until a patch is applied. There are no known workarounds for this vulnerability. Users are advised to upgrade to a patched version to mitigate the risk.

Exploit

Fix

Improper Handling of Exceptional Conditions

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-02869
CVE-2023-32314
GHSA-WHPJ-8F3W-67P5

Affected Products

Vm2