CVE-2022-36067

Scores

EPSS

0.848high84.8%
0%20%40%60%80%100%

Percentile: 84.8%

CVSS

10.0critical3.x
0246810

CVSS Score: 10.0/10

All CVSS Scores

CVSS 3.x
10.0

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

vm2 is a sandbox that can run untrusted code with whitelisted Node’s built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-913

Related Vulnerabilities

Exploits

Exploit ID: CVE-2022-36067

Source: github-poc

URL: https://github.com/Prathamrajgor/Exploit-For-CVE-2022-36067

Vulnerable Software (1)

Type: Configuration

Vendor: *

Product: vm2

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:vm2_project:vm2:*:*:*:*:*:node.js:*:*",      "versionEndExcluding": "3.9.11",      "vulnerable": true    }  ],  "operator": "OR"}

Source: nvd

End of list