HIGH · 8.2

CVE-2020-24718

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonst...

Vulnerability Description

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.

CVSS Score

8.2

HIGH

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
FreebsdFreebsd<= 11.2
OmniosceOmnios<= r151034
OpenindianaOpenindiana<= hipster_2020.04
NetappClustered Data Ontap-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-24718?

CVE-2020-24718 is a vulnerability with a CVSS score of 8.2 (HIGH). bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonst...

How severe is CVE-2020-24718?

CVE-2020-24718 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-24718?

Check the references section above for vendor advisories and patch information. Affected products include: Freebsd Freebsd, Omniosce Omnios, Openindiana Openindiana, Netapp Clustered Data Ontap.