CRITICAL

CVE-2023-29199

CVSS v3

10

CRITICAL

EPSS Score

25.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.16` of `vm2`.

Technical details

Published
4/14/2023

Frequently asked questions

What is CVE-2023-29199?

There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass `handleException()` and leak unsanitized host exceptions which can be used to escape the sandbox and run arbitrary code in host context. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version `3.9.16` of `vm2`.

Is CVE-2023-29199 actively exploited?

Active exploitation of CVE-2023-29199 has not been confirmed. The EPSS score is 25.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-29199?

CVE-2023-29199 has a CVSS v3 base score of 10 (CRITICAL severity).

Is CVE-2023-29199 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.