RSS   Vulnerabilities for 'Hypervisor introspection'   RSS

2020-12-17
 
CVE-2020-15294

NVD-CWE-Other
 

 
Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results in multiple dereferences to the same pointer. If the pointer is located in memory-mapped from the guest space, this may cause a race-condition where the generated code would dereference the same address twice, thus obtaining different values, which may lead to arbitrary code execution. This issue affects: Bitdefender Hypervisor Introspection versions prior to 1.132.2.

 
 
CVE-2020-15293

CWE-20
 

 
Memory corruption in IntLixCrashDumpDmesg, IntLixTaskFetchCmdLine, IntLixFileReadDentry and IntLixFileGetPath due to insufficient guest-data input validation may lead to denial of service conditions.

 
 
CVE-2020-15292

CWE-20
 

 
Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTaskDumpTree may lead to out-of-bounds read or it could cause DoS due to integer-overflor (IntPeGetDirectory), TOCTOU (IntPeParseUnwindData) or insufficient validations.

 

 >>> Vendor: Bitdefender 22 Products
Bitdefender client
Antivirus
Internet security
Total security
Online anti-virus scanner
Update server
Bitdefender
Bitdefender antivirus
Bitdefender total security 2010
Gravityzone
Antivirus plus
Internet security 2018
Safepay
Central
Endpoint security tools
Total security 2020
Antivirus for mac
Antimalware software development kit
Antivirus 2020
Engines
Endpoint security
Hypervisor introspection


Copyright 2021, cxsecurity.com

 

Back to Top