CVE-2020-24718
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862
- Affected
- freebsd/freebsd · omniosce/omnios · openindiana/openindiana · netapp/clustered data ontap
- Source
- cve@mitre.org
References
- https://github.com/illumos/illumos-gate/blob/84971882a96ac0fecd538b02208054a872ff8af3/usr/src/uts/i86pc/io/vmm/intel/vmcs.c#L246-L249Exploit, Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:28.bhyve_vmcs.ascVendor Advisory
- https://security.netapp.com/advisory/ntap-20201016-0002/Third Party Advisory
- https://github.com/illumos/illumos-gate/blob/84971882a96ac0fecd538b02208054a872ff8af3/usr/src/uts/i86pc/io/vmm/intel/vmcs.c#L246-L249Exploit, Third Party Advisory
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:28.bhyve_vmcs.ascVendor Advisory
- https://security.netapp.com/advisory/ntap-20201016-0002/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.