home.social

#sandboxescape — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sandboxescape, aggregated by home.social.

  1. vm2 Library Vulnerabilities Enable Sandbox Escape and Code Execution

    A dozen critical vulnerabilities in the vm2 Node.js library can be exploited by hackers to break free from sandbox restrictions and run malicious code on vulnerable systems. This serious security flaw has been assigned high CVSS scores, emphasizing the urgent need for users to patch their systems.

    osintsights.com/vm2-library-vu

    #Nodejs #Vm2Library #SandboxEscape #CodeExecution #Cve202624118

  2. 🚨​ [#PatchNow] New VM2 #SandboxEscape... Two critical vulns are out in the #VM2 #Sandbox Library. These flaws affect all versions prior to 3.9.17 and both carry a CVSS score of 9.8.

    If exploited, a threat actor could escape protection boundaries and execute arbitrary code. A patch has been released. so get it and update: bleepingcomputer.com/news/secu.

    These two CVEs (CVE-2023-29199 and CVE-2023-30547) were discovered by Seung Hyun Lee.

    nvd.nist.gov/vuln/detail/CVE-2

    nvd.nist.gov/vuln/detail/CVE-2

    #infosec #patchmanagement #riskmitigation