CVE-2025-71323: picklescan - Remote Code Execution via Unblocked ctypes Module
picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls and accessing raw memory. Attackers can craft malicious pickle files using ctypes.WinDLL to load kernel32.dll and execute arbitrary commands, bypassing sandbox protections and gadget chain detection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
picklescanto a version that resolves this vulnerability.Fixed in 0.0.33
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71323?
CVE-2025-71323 has a critical severity level of 9.3.
How do I fix CVE-2025-71323?
To remediate CVE-2025-71323, upgrade picklescan to version 0.0.33 or later.
What type of vulnerability is CVE-2025-71323?
CVE-2025-71323 is a remote code execution vulnerability caused by the failure to block the ctypes module in picklescan.
What can attackers do with CVE-2025-71323?
Attackers can exploit CVE-2025-71323 to execute arbitrary commands and access raw memory via malicious pickle files.
Which software is affected by CVE-2025-71323?
CVE-2025-71323 affects picklescan versions prior to 0.0.33.