PT-2020-15829 · Intel+4 · Intel+5
Published
2020-09-15
·
Updated
2022-01-01
·
CVE-2020-24718
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
bhyve versions prior to the fixed version in FreeBSD through 12.1
bhyve as used in illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04)
Description
The issue is related to the improper restriction of VMCS and VMCB read/write operations. This can be exploited by a root user in a container on an Intel system to gain privileges by modifying VMCS HOST RIP.
Recommendations
For bhyve as used in FreeBSD through 12.1, update to a version that includes the fix for this issue.
For bhyve as used in illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), consider restricting access to VMCS and VMCB operations until a patch is available.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd
Intel
Omnios Ce
Openindiana
Bhyve
Illumos