Summary:
If you use plugins in VaM, please update immediately to VaM 1.22.0.12 to get important security updates
Background:
We were alerted by community member SPQR of an additional security risk in the plugin system still present in our last release. We always appreciate when members of the community contact us directly when they find security risks and provide details to aid us with creating a patch to address them.
The plugin system is the system that allows you to load 3rd party community created code within VaM. In security patches like this one we are adding additional restrictions to this plugin system to prevent 3rd party code from having access to things they shouldn't have access to.
In additional, our last release broke a couple of community created plugins due to a mistake in one of the security restrictions we put in. We wanted to put a patch out to address this and allow those plugins to work again.
We will continue to patch VaM1 over time as needed for security updates while VaM2 continues to be the main focus.
How to get the patch:
Simply run VaM_Updater.exe in your VaM install folder and click the button at the bottom right to update to 1.22.0.12.
Security risks addressed in this patch:
Plugins could use a specific method to write files outside of VaM's secure sandbox. We have blocked this additional method that was discovered. Plugins are normally restricted to only being able to write to specific folders in your VaM install folder.
Blocked additional methods for plugins to access specific parts of our internal code that plugins should not have access to.
Additional Fix/Tweak:
Fixed one of the restrictions introduced in the last patch that broke a few plugins. We now allow a specific safe method exception that was needed by those plugins.
Recommendations if you use plugins in VaM:
Immediately patch to 1.22.0.12
Use the "Allow Plugins Network Access" preference with caution, as it poses the most risk in usage of all the user preferences. This option is disabled by default.
Never run VaM with administrator privileges.
If you are still concerned about security risks, you can disable plugins completely. Plugins are disabled by default. If you do use plugins consider running VaM with a dedicated user account that you don't use for anything else besides VaM. An alternative is to run VaM in a sandbox application like sandboxie.
Only load content from sources you trust.
More Info:
We are done actively looking for security holes and do not have any more security patches planned. We will, however, make more patches as needed if we are alerted to additional risks.
We have scanned all of the Hub-hosted plugins, and as expected, none of the Hub-hosted plugins are using any of these methods in a malicious way.
At this time, we are not giving more specifics on exactly what the patch restricts to give users time to apply the patch to their installs before malicious actors have a chance to act on this info.