TechNews Pictorial PriceGrabber Video Fri Nov 29 10:46:33 2024

0


US-CERT warns of guest-to-host VM escape vulnerability
Source: l33tdawg


The U.S. Computer Emergency Readiness Team (CERT) has issued an alert for a dangerous guest-to-host virtual machine escape vulnerability affecting virtualization software from multiple vendors.

The vulnerability, which affects 64-bit operating systems and virtualization software running on Intel CPU hardware, exposes users to local privilege escalation attack or a guest-to-host virtual machine escape.

From the advisory:follow Ryan Naraine on twitter

        A ring3 attacker may be able to specifically craft a stack frame to be executed by ring0 (kernel) after a general protection exception (#GP). The fault will be handled before the stack switch, which means the exception handler will be run at ring0 with an attacker’s chosen RSP causing a privilege escalation.


}

© 2021 PopYard - Technology for Today!| about us | privacy policy |