HomeSecurityPoC exploit published for critical vulnerabilities in Lua engine

PoC exploit published for critical vulnerabilities in Lua engine

Three new vulnerabilities have been discovered in the Lua scripting engine of Redis 7.4.5, each of which poses serious risks for remote code execution and privilege escalation. Redrays published a detailed proof-of-concept (PoC) exploit for these vulnerabilities, but it is no longer available to the public. However, organizations are urged to take immediate action to protect their systems.

PoC exploit Lua Engine Redis

Lua scripting engine – Redis: Use-After-Free vulnerability (CVE-2025-49844)

This vulnerability occurs when TString objects are not properly protected during script parsing. Specifically, in luaY_parser, the Lua parser fails to protect a new TString, making it vulnerable to “premature garbage collection” and “use-after-free conditions.” Attackers can exploit this issue for remote code execution.

See also: CISA added Zimbra vulnerability to KEV Catalog

Lua scripting engine – Redis: Integer Overflow (CVE-2025-46817)

The unpack() function incorrectly calculates the number of elements, allowing stack corruption when called with extreme range parameters. By modifying the arguments, such as unpack({1,2,3}, -2, 2147483647), attackers could bypass array bounds and execute arbitrary code.

Lua scripting engine: Metatable  Privilege Escalation Vulnerability (CVE-2025-46818)

This vulnerability allows modification of basic metatables, such as those for strings and numbers, because they are not properly protected (as read-only). By modifying the metatables, a malicious user could achieve privilege escalation or code execution in the context of other users.

PoC exploit published for critical vulnerabilities in Lua engine

RedRays said a robust Python-based PoC exploit verifies the criticality of all three vulnerabilities. The PoC automates:

  • Fuzzing of unpack() call to cause integer overflow and stack corruption (CVE-2025-46817)
  • Manipulation of basic metatables types to demonstrate privilege escalation via crafted Lua scripts (CVE-2025-46818)

See also: Vulnerability in Kibana Crowdstrike Connector exposes protected credentials

The code connects to a targeted Redis instance and runs up to ten full-stack tests, confirming exploitability and the presence or absence of a proper patch.

These technical checks leverage custom Lua scripts sent via Redis EVAL commands, revealing vulnerable server states.

See also: Exploiting OpenSSH vulnerability via ProxyCommand

PoC exploit published for critical vulnerabilities in Lua engine

Protection

Redis administrators should update to patched versions immediately. These CVEs collectively expand the attack surface of Redis, exposing production servers to real threats, especially where EVAL access is available. Organizations running Redis 7.4.5 should deploy patches without delay, as attackers can exploit these vulnerabilities to achieve full remote code execution and unauthorized privilege escalation. Immediate patching is required for all Redis deployments that are exposed to the internet (or untrusted).

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS