360 Total Security 3.5.0.1033 allows a Sandbox Escape via an import os statement, followed by os.system(CMD) or os.system(PowerShell), within a .py file. NOTE: the vendors position is that this cannot be categorized as a vulnerability, although it is a security-related issue
Name | Vendor | Start Version | End Version |
---|---|---|---|
360_total_security | 360totalsecurity | 3.5.0.1033 (including) | 3.5.0.1033 (including) |