CVE-2023-29199: vm2 Sandbox escape vulnerability
There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass handleException() and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context.
Impact A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.
Patches This vulnerability was patched in the release of version 3.9.16 of vm2.
Workarounds None.
References Github Issue - https://github.com/patriksimek/vm2/issues/516 PoC - https://gist.github.com/leesh3288/f05730165799bf56d70391f3d9ea187c
For more information
If you have any questions or comments about this advisory:
- Open an issue in VM2
Thanks to Xion (SeungHyun Lee) of KAIST Hacking Lab for disclosing this vulnerability.
Other sources
There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass handleException() and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.16 of vm2.
— MITRE
There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass handleException() and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-29199?
CVE-2023-29199 has a high severity due to the potential for arbitrary code execution and sandbox escape.
How do I fix CVE-2023-29199?
To fix CVE-2023-29199, upgrade to vm2 version 3.9.16 or later.
What versions are affected by CVE-2023-29199?
CVE-2023-29199 affects vm2 versions up to and including 3.9.15.
What is the impact of CVE-2023-29199?
The impact of CVE-2023-29199 is that it allows attackers to bypass exception handling and leak unsanitized host exceptions.
What is the main exploit of CVE-2023-29199?
The main exploit of CVE-2023-29199 is the ability to run arbitrary code in the host context through sandbox escape.