Vulnerabilities > CVE-2020-24718 - Missing Authorization vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
HIGH Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://github.com/illumos/illumos-gate/blob/84971882a96ac0fecd538b02208054a872ff8af3/usr/src/uts/i86pc/io/vmm/intel/vmcs.c#L246-L249
- https://github.com/illumos/illumos-gate/blob/84971882a96ac0fecd538b02208054a872ff8af3/usr/src/uts/i86pc/io/vmm/intel/vmcs.c#L246-L249
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:28.bhyve_vmcs.asc
- https://security.FreeBSD.org/advisories/FreeBSD-SA-20:28.bhyve_vmcs.asc
- https://security.netapp.com/advisory/ntap-20201016-0002/
- https://security.netapp.com/advisory/ntap-20201016-0002/