ZeroHour

CVE-2020-24718

PoC
CVSS 3.1
8.2 high
EPSS
<1%p47
Published
()
Modified
Description

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.

Vendors
freebsdomniosceopenindiananetapp
Products
freebsd, omnios, openindiana, clustered data ontap
Weakness
CWE-862
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.