A mix-up of the critical severity type in the isolated VM’s Node.js library could allow threat actors to achieve Remote Code Execution (RCE) on the host system.
Isolated-vm allows developers to access the V8 JavaScript engine’s Isolate interface to create completely isolated JavaScript environments. Each Isolate is a completely separate V8 instance with its own heap, execution state, and garbage collector.
V8’s Isolates made it possible to run multiple sandboxed JavaScript code instances on the same machine without the need for a container or virtual machine. isolated-vm is often used to run untrusted JavaScript code within a V8 isolate.
The recently identified type confusion bug, which has not yet been assigned a CVE identifier, impacts ExternalCopy, the data copying feature between Isolates and EndorLabs explained. The function serializes the data in one isolate and reconstructs it in the other instance.
To optimize performance, a transfer list is used: large ArrayBuffers are enumerated, and the underlying memory is transferred by separating the buffer from the source and passing it to the destination.
The problem was that when transferring data, the reconstructor went through the byte array list twice, with the second pass trusting the first pass.
However, because iterating the JavaScript transfer_list array would not return the same value for an element defined as a getter on each pass, an attacker could abuse the Time-of-Check/Time-of-Use (TOCTOU) vulnerability to dereference an attacker-controlled pointer.
While the ExternalCopy constructor can only be accessed from the host, a guest can target ivm.Reference, the mechanism through which the host exposes everything to the sandbox, to create the malicious TransferList and trigger the vulnerability, EndorLabs says.
Successful exploitation of the vulnerability results in a denial of service or control flow hijack of the host process, potentially enabling RCE on the host.
“Any embedder that runs untrusted code in an isolate and shares even a reference within it is affected. Host code that passes a caller-influenced array as a TransferList is directly affected without a guest present,” an isolated VM advisory reads.
Patches for the vulnerability have been included in Insulated VM versions 6.2.0 and 7.0.1 to prevent user JavaScript from running during the copy process.
“The vulnerability was in the native glue code: the C++ binding that serializes values across the boundary. This layer is written in a memory-insecure language; it manipulates raw V8 handles and backing store pointers and rereads attacker-controlled JavaScript objects in the middle of a security-sensitive operation. A single unchecked cast to a reread value was enough to convert a correct isolation primitive into a full escape,” noted EndorLabs.
Related: Rust supply chain attack linked to North Korean hackers
Related: Microsoft is rolling out 22 new security patches
Related: CISA urges immediate patching of exploited TrueConf vulnerabilities
Related: Atlassian and Splunk patch dozens of critical, high-severity vulnerabilities
