Patch Released for Critical vm2 Sandbox Escape Vulnerability
ID: 89e9ebbb-37ac-5a5f-a320-d4a96a885722
STIX ID: report--89e9ebbb-37ac-5a5f-a320-d4a96a885722
Feed Name: FortiGuard Threat Signals
Threat Score
This advisory reports multiple critical sandbox escape vulnerabilities in the vm2 Node.js module (CVE-2023-29017, CVE-2023-29199, CVE-2023-30547) with CVSS scores of 9.8 that can allow remote code execution from within a sandbox; PoCs are publicly available and fixes were released (vm2 3.9.16 and 3.9.17), so users should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
