Permissions, Privileges, and Access Controls in Script Security - CVE-2019-10355
Published: October 3, 2019 / Updated: October 7, 2019
Script Security
Detailed vulnerability description
The vulnerability allows a remote attacker to escalate privileges on the system.
The vulnerability exists due to the sandbox protection can be circumvented by casting crafted objects to other types. A remote authenticated attacker who is able to specify sandboxed scripts can invoke constructors that were not whitelisted and execute arbitrary code on the target system.