CVE-2020-24718

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.2 HIGH
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
VendorProductVersion
freebsdfreebsd
𝑥
≤ 11.2
freebsdfreebsd
11.3
freebsdfreebsd
11.3:p1
freebsdfreebsd
11.3:p10
freebsdfreebsd
11.3:p11
freebsdfreebsd
11.3:p12
freebsdfreebsd
11.3:p13
freebsdfreebsd
11.3:p2
freebsdfreebsd
11.3:p3
freebsdfreebsd
11.3:p4
freebsdfreebsd
11.3:p5
freebsdfreebsd
11.3:p6
freebsdfreebsd
11.3:p7
freebsdfreebsd
11.3:p8
freebsdfreebsd
11.3:p9
freebsdfreebsd
11.3:rc3
freebsdfreebsd
11.4
freebsdfreebsd
11.4:beta1
freebsdfreebsd
11.4:p1
freebsdfreebsd
11.4:p2
freebsdfreebsd
11.4:p3
freebsdfreebsd
11.4:rc1
freebsdfreebsd
11.4:rc2
freebsdfreebsd
12.0
freebsdfreebsd
12.0:p1
freebsdfreebsd
12.0:p10
freebsdfreebsd
12.0:p11
freebsdfreebsd
12.0:p12
freebsdfreebsd
12.0:p2
freebsdfreebsd
12.0:p3
freebsdfreebsd
12.0:p4
freebsdfreebsd
12.0:p5
freebsdfreebsd
12.0:p6
freebsdfreebsd
12.0:p7
freebsdfreebsd
12.0:p8
freebsdfreebsd
12.0:p9
freebsdfreebsd
12.1
freebsdfreebsd
12.1:p1
freebsdfreebsd
12.1:p2
freebsdfreebsd
12.1:p3
freebsdfreebsd
12.1:p4
freebsdfreebsd
12.1:p5
freebsdfreebsd
12.1:p6
freebsdfreebsd
12.1:p7
freebsdfreebsd
12.1:p8
freebsdfreebsd
12.1:p9
omniosceomnios
𝑥
≤ r151034
netappclustered_data_ontap
-
𝑥
= Vulnerable software versions