CVE-2023-43338
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Sep 23, 2023
Updated: Sep 26, 2023
CWE ID 787
Summary
CVE-2023-43338 is a function pointer hijacking vulnerability affecting Cesanta mjs v2.20.0. The issue lies within the function mjs_get_ptr(), which can be exploited by attackers to execute arbitrary code. By providing a crafted input, they can hijack the function pointer and redirect its execution to their own malicious code. This vulnerability poses a significant risk and requires immediate attention from users to apply the necessary patches or updates.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Cesanta Software Limited