PT-2020-15829 · Intel+4 · Intel+5

Published

2020-09-15

·

Updated

2022-01-01

·

CVE-2020-24718

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions bhyve versions prior to the fixed version in FreeBSD through 12.1 bhyve as used in illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04)
Description The issue is related to the improper restriction of VMCS and VMCB read/write operations. This can be exploited by a root user in a container on an Intel system to gain privileges by modifying VMCS HOST RIP.
Recommendations For bhyve as used in FreeBSD through 12.1, update to a version that includes the fix for this issue. For bhyve as used in illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), consider restricting access to VMCS and VMCB operations until a patch is available.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-24718
FREEBSD-SA-20_28

Affected Products

Freebsd
Intel
Omnios Ce
Openindiana
Bhyve
Illumos