Local EoP within host/guest OS is one of the lesser known attack vectors in the virtualization systems’ threat model. Vulns like that one are actually quite common, although usually it’s classical memory corruptions in the hypervisor r0 drivers rather than systemwide logic issueshttps://twitter.com/alisaesage/status/1303362581583732736 …
-
Show this thread
-
And by the way, of all modern virtualization systems Hyper-V has the widest attack surface in the kernel space (of which storvsp.sys is just one module), which MS guys don’t usually accentuate in their Hyper-V research blogs for some reason
1 reply 7 retweets 21 likesShow this thread -
Replying to @alisaesage
when patched you get to see how to do file operations on hyper-v host hd from guest container os
1 reply 0 retweets 0 likes
Replying to @jonasLyk @alisaesage
only 20 k bounty- i have no idea why, but ms ipc always ruins my mood so havent asked
7:59 AM - 9 Sep 2020
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.