Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40552
HistoryMay 17, 2023 - 12:31 a.m.

Remote Code Execution (RCE)

2023-05-1700:31:21
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
vm2
rce vulnerability
host object creation
sandbox
arbitrary code
software

0.013 Low

EPSS

Percentile

86.0%

vm2 is vulnerable to Remote Code Execution (RCE). The vulnerability is due to the unexpected creation of a host object based on the proxy specification, which allows an attacker to break out of the sandbox and execute arbitrary code on the host system.

CPENameOperatorVersion
vm2le3.9.17
vm2le3.9.17

0.013 Low

EPSS

Percentile

86.0%