Researchers Discover Critical Remote Code Execution Flaw in vm2 Sandbox Library

Cyber Security

Products You May Like

Apr 08, 2023Ravie LakshmananVulnerability / Software

The maintainers of the vm2 JavaScript sandbox module have shipped a patch to address a critical flaw that could be abused to break out of security boundaries and execute arbitrary shellcode.

The flaw, which affects all versions, including and prior to 3.9.14, was reported by researchers from South Korea-based KAIST WSP Lab on April 6, 2023, prompting vm2 to release a fix with version 3.9.15 on Friday.

“A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox,” vm2 disclosed in an advisory.

The vulnerability has been assigned the identified CVE-2023-29017 and is rated 9.8 on the CVSS scoring system. The issue stems from the fact that it does not properly handle errors that occur in asynchronous functions.

vm2 is a popular library that’s used to run untrusted code in an isolated environment on Node.js. It has nearly four million weekly downloads and is used in 721 packages.

UPCOMING WEBINAR

Learn to Secure the Identity Perimeter – Proven Strategies

Improve your business security with our upcoming expert-led cybersecurity webinar: Explore Identity Perimeter strategies!

Don’t Miss Out – Save Your Seat!

KAIST security researcher Seongil Wi has also made available two different variants of a proof-of-concept (PoC) exploit for CVE-2023-29017 that get around the sandbox protections and allow the creation of an empty file named “flag” on the host.

The disclosure comes almost six months after vm2 resolved another critical bug (CVE-2022-36067, CVSS score: 10) that could have been weaponized to perform arbitrary operations on the underlying machine.

Found this article interesting? Follow us on Twitter and LinkedIn to read more exclusive content we post.

Products You May Like

Articles You May Like

OnePlus Nord 4 to Launch Alongside Pad 2, Watch 2R, and Nord Buds 3 Pro on July 16
FakeBat Loader Malware Spreads Widely Through Drive-by Download Attacks
Samsung Galaxy M35, iQoo Z9 Lite, Honor 200, and More New Smartphones to Go on Sale During Amazon Prime Day 2024
GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks
Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus

Leave a Reply

Your email address will not be published. Required fields are marked *