CVE-2021-44078 is a high-severity vulnerability in the Unicorn Engine (before version 2.0.0-rc5) that allows local attackers to escape the sandbox. The flaw resides in the virtual memory manager's split_region function, specifically a faulty comparison of GVA and GPA during memory block freeing. This enables an attacker, who has already gained code execution within the sandbox, to execute arbitrary code on the host machine. The vulnerability has a CVSS score of 8.1 (High), indicating a local attack vector with high complexity, but leading to high impact on confidentiality, integrity, and availability. Despite its severity, there is currently no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.3CPE matchmatch criteria | cpe:2.3:a:unicorn-engine:unicorn_engine:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:unicorn-engine:unicorn_engine:2.0.0:rc1:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:unicorn-engine:unicorn_engine:2.0.0:rc2:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:unicorn-engine:unicorn_engine:2.0.0:rc3:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:unicorn-engine:unicorn_engine:2.0.0:rc4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.