CVE-2023-43338

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Sep 23, 2023
Updated: Sep 26, 2023
CWE ID 787

Summary

CVE-2023-43338 is a function pointer hijacking vulnerability affecting Cesanta mjs v2.20.0. The issue lies within the function mjs_get_ptr(), which can be exploited by attackers to execute arbitrary code. By providing a crafted input, they can hijack the function pointer and redirect its execution to their own malicious code. This vulnerability poses a significant risk and requires immediate attention from users to apply the necessary patches or updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share