CVE-2020-24718Missing Authorization in Freebsd

Severity
8.2HIGHNVD
EPSS
0.1%
top 72.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 25
Latest updateMay 24

Description

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0

Affected Packages3 packages

NVDfreebsd/freebsd11.2+4
NVDomniosce/omniosr151034
NVDopenindiana/openindianahipster_2020.04

🔴Vulnerability Details

2
GHSA
GHSA-g73j-h828-gg82: bhyve, as used in FreeBSD through 122022-05-24
CVEList
CVE-2020-24718: bhyve, as used in FreeBSD through 122020-09-25

📋Vendor Advisories

1
BSD
FreeBSD-SA-20:28.bhyve_vmcs: bhyve privilege escalation via VMCS access2020-09-15
CVE-2020-24718 — Missing Authorization in Freebsd | cvebase