CVE-2022-25893: Arbitrary Code Execution
Published Dec 21, 2022
·Updated
The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.
Affected Software
1 affected component
Vm2 Project Vm2 Node.js<3.9.10
Remediation
Patch Available
Patch Available
Event History
Dec 21, 2022
CVE Published
05:15 AM
Data Sourced
via NVD·05:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·11:14 PM
Data Sourced
via MITRE·11:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-25893?
CVE-2022-25893 has a severity rating of high due to its potential for arbitrary code execution.
2
How do I fix CVE-2022-25893?
To mitigate CVE-2022-25893, upgrade the vm2 package to version 3.9.10 or later.
3
What causes the vulnerability described in CVE-2022-25893?
CVE-2022-25893 is caused by the use of prototype lookup for the WeakMap.prototype.set method.
4
What could an attacker achieve by exploiting CVE-2022-25893?
An attacker could achieve arbitrary code execution, leading to access to host objects and sandbox compromise.
5
Which versions of the vm2 package are affected by CVE-2022-25893?
All versions of the vm2 package prior to 3.9.10 are affected by CVE-2022-25893.