PT-2023-2909 · Vm2 · Vm2

Arkark

+1

·

Published

2023-05-15

·

Updated

2026-01-30

·

CVE-2023-32314

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions vm2 versions up to and including 3.9.17
Description A sandbox escape issue exists in vm2, allowing a threat actor to bypass sandbox protections and gain remote code execution rights on the host. This is achieved by abusing an unexpected creation of a host object based on the specification of Proxy. The vulnerability can be exploited by a remote attacker to execute arbitrary code.
Recommendations For versions up to and including 3.9.17, upgrade to version 3.9.18 or later to patch the vulnerability. As a temporary workaround, consider restricting access to the Proxy specification until a patch is applied. There are no known workarounds for this vulnerability. Users are advised to upgrade to a patched version to mitigate the risk.

Exploit

Fix

Special Elements Injection

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2023-02869
CVE-2023-32314
GHSA-WHPJ-8F3W-67P5

Affected Products

Vm2