CVE-2020-24718 Information
Feb 14, 2021
cve
Description
bhyve as used in FreeBSD through 12.1 and illumos (e.g. OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04) does not properly restrict VMCS and VMCB read/write operations as demonstrated by a root user in a container on an Intel system who can gain privileges by modifying VMCS_HOST_RIP.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Reference
https://github.com/illumos/illumos-gate/blob/84971882a96ac0fecd538b02208054a872ff8af3/usr/src/uts/i86pc/io/vmm/intel/vmcs.cL246-L249 https://security.FreeBSD.org/advisories/FreeBSD-SA-20:28.bhyve_vmcs.asc https://security.netapp.com/advisory/ntap-20201016-0002/
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.2
Share on: