Critical VM escape vulnerability impacts business systems, data centers

The vulnerability, dubbed Venom, affects systems usings the QEMU, Xen and KVM virtualization platforms

A critical vulnerability in code used by several virtualization platforms can put business information stored in data centers at risk of compromise.

The flaw, dubbed Venom but tracked as CVE-2015-3456, can allow an attacker to break out from the confines of a virtual machine (VM) and execute code on the host system.

This security boundary is critical in protecting the confidentiality of data in data centers, where virtualization is extensively used to allow different tenants to run servers on the same physical hardware.

The flaw is located in the virtual Floppy Disk Controller (FDC) code from the QEMU open source machine emulator and virtualizer. The code is also used by the Xen, KVM and other virtualization platforms.

The VMware, Microsoft Hyper-V, and Bochs hypervisors are not impacted by the vulnerability, according security firm CrowdStrike, whose senior security researcher, Jason Geffner, found the issue.

There have been other VM escape vulnerabilities discovered over the years, but this one stands apart because it affects multiple virtualization platforms in default configurations and is agnostic to the guest or host operating system.

Attackers do need to have root access on the guest OS in order to exploit the flaw and execute code on the hypervisor. But once this is done, they could gain access to other servers running on the same hypervisor or to the network traffic originating from all virtual machines.

Because of a separate bug, on Xen and QEMU the vulnerable FDC code remains active even if the administrator disables the virtual floppy drive for a virtual machine, CrowdStrike said.

The QEMU and Xen projects released patches to address this vulnerability.

"While I do consider the vulnerability severe and recommend system administrators to apply fixes when available -- especially in environments where potentially untrusted users have access to guests with administrative privileges -- I also find it blown out of proportions," said Carsten Eiram, the chief research officer of vulnerability intelligence firm Risk Based Security, via email.

Having to first obtain root/administrator access on the guest system makes the vulnerability harder to exploit because an external attacker would need to chain the flaw with a different vulnerability for the guest OS, Eiram said. Also, it's worth noting that ARM platforms are not affected, he said.

The security team from Red Hat said in a blog post that while in theory the vulnerability has the potential to be used for code execution, it hasn't seen any working exploit that demonstrates this.

"To be able to break out of a guest OS to a host OS is a rare and powerful ability, and such bugs are uncommon," said Tod Beardsley, research manager at Rapid7, via email. "Given this incentive of interestingness, I would expect to see a public proof of concept exploit appear sooner rather than later."

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags patchesCrowdStrikesecurityRapid7Risk Based Securitypatch managementRed HatExploits / vulnerabilitiesdata protection

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?