CVE-2021-41556
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An attacker might abuse this bug to target (for example) Cloud services that allow customization via SquirrelScripts, or distribute malware through video games that embed a Squirrel Engine.
El archivo sqclass.cpp en Squirrel versiones hasta 2.2.5 y 3.x hasta 3.1 permite una lectura fuera de límites (en el intérprete del núcleo) que puede conllevar a una ejecución de código. Si una víctima ejecuta un script de Squirrel controlado por un atacante, es posible que el atacante salga del sandbox del script de Squirrel incluso si toda la funcionalidad peligrosa, como las funciones del sistema de archivos, ha sido deshabilitada. Un atacante podría abusar de este fallo para dirigirse (por ejemplo) a servicios en la nube que permitan la personalización por medio de SquirrelScripts, o distribuir malware mediante videojuegos que incorporen un Squirrel Engine
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-09-22 CVE Reserved
- 2022-07-28 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-10-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://www.squirrel-lang.org/#download | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://blog.sonarsource.com/squirrel-vm-sandbox-escape | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://github.com/albertodemichelis/squirrel/commit/23a0620658714b996d20da3d4dd1a0dcf9b0bd98 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Squirrel-lang Search vendor "Squirrel-lang" | Squirrel Search vendor "Squirrel-lang" for product "Squirrel" | <= 2.2.5 Search vendor "Squirrel-lang" for product "Squirrel" and version " <= 2.2.5" | - |
Affected
| ||||||
Squirrel-lang Search vendor "Squirrel-lang" | Squirrel Search vendor "Squirrel-lang" for product "Squirrel" | >= 3.0 <= 3.1 Search vendor "Squirrel-lang" for product "Squirrel" and version " >= 3.0 <= 3.1" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 35 Search vendor "Fedoraproject" for product "Fedora" and version "35" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 36 Search vendor "Fedoraproject" for product "Fedora" and version "36" | - |
Affected
|