PT-2023-2909 · Vm2 · Vm2
Arkark
+1
·
Published
2023-05-15
·
Updated
2026-01-30
·
CVE-2023-32314
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
vm2 versions up to and including 3.9.17
Description
A sandbox escape issue exists in vm2, allowing a threat actor to bypass sandbox protections and gain remote code execution rights on the host. This is achieved by abusing an unexpected creation of a host object based on the specification of
Proxy. The vulnerability can be exploited by a remote attacker to execute arbitrary code.Recommendations
For versions up to and including 3.9.17, upgrade to version 3.9.18 or later to patch the vulnerability. As a temporary workaround, consider restricting access to the
Proxy specification until a patch is applied. There are no known workarounds for this vulnerability. Users are advised to upgrade to a patched version to mitigate the risk.Exploit
Fix
Special Elements Injection
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vm2