CVE-2020-24718

HIGH

FreeBSD through 12.1 - Missing Authorization in bhyve VMCS/VMCB Operations

Title source: llm
STIX 2.1

Description

bhyve, as used in FreeBSD through 12.1 and illumos (e.g., OmniOS CE through r151034 and OpenIndiana through Hipster 2020.04), does not properly restrict VMCS and VMCB read/write operations, as demonstrated by a root user in a container on an Intel system, who can gain privileges by modifying VMCS_HOST_RIP.

Scores

CVSS v3 8.2
EPSS 0.0010
EPSS Percentile 27.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-862
Status published
Products (8)
freebsd/freebsd 11.3 (15 CPE variants)
freebsd/freebsd 11.4 (7 CPE variants)
freebsd/freebsd 12.0 (13 CPE variants)
freebsd/freebsd 12.1 (10 CPE variants)
freebsd/freebsd < 11.2
netapp/clustered_data_ontap
omniosce/omnios < r151034
openindiana/openindiana < hipster_2020.04
Published Sep 25, 2020
Tracked Since Feb 18, 2026