There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.16` of `vm2`.
CVE Infomation | Exploits or more Infomation |
---|---|
mitre | EXPLOIT DATABASE |
NVD | 0day.today |
vulmon.com | github |
CVE Details | |
JVN ENG JPN | |
Reconshell |
Software Tag:
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
http://cyberiqs.com/latestnews | 65 |
https://securityonline.info/cve-2023-29199-critical-sandbox... | 3 |
List of frequently cited URLs
URL | Num of Times Referred to |
---|---|
cyberiqs.com | 65 |
securityonline.info | 3 |
Name | URL |
---|---|
No Data |
Name | URL |
---|---|
No Data |