“All bets are off” with new VMware escape flaw

Vulnerabilities exposed in VMware’s software could lead to attackers taking control of any virtual machine that shares the same hypervisor.

The critical flaw means customers using shared hosting environments could be exposed if other virtual machines within the same environment are exploited.

Security experts say the flaw is about as dangerous as the come. “If you can escape to the hypervisor you can access every system,” wrote security researcher Kevin Beaumont on Mastodon.

“For example, providers like MSPs sell VMware Clouds, where multiple customers share physical hosts. If you can escape to the hypervisor, all bets are off as a boundary is broken.

Beaumont added that “if it was Azure and it was a HyperV escape (different product), youโ€™d be able to use any Azure customer to compromise everybody on Azure. Thatโ€™s why MS pays very well for HyperV escapes.”

“With this vuln youโ€™d be able to use it to traverse VMware managed hosting providers, private clouds orgs have built on prem etc.”

VMware escape flaw being exploited in the wild

This isn’t a merely theoretical threat, either, with VMware’s advisory notice stating that “Broadcom has information to suggest that exploitation of these issues has occurred ‘in the wild’.”

The vulnerabilities affect a wide range of the company’s products, including VMware ESX, vSphere, Cloud Foundation and Telco Cloud Platform. The company describes the patches as an “emergency change, requiring prompt action from your organisation”.

VMware’s advisory makes clear that the threat described by Beaumont is not overstated, describing it as a “VM escape”.

“This is a situation where an attacker who has already compromised a virtual machineโ€™s guest OS and gained privileged access (administrator or root) could move into the hypervisor itself,” the advisory states.

Protection advice from our experts

Avatar photo
Barry Collins

Barry has 25 years of experience working on national newspapers, websites and magazines. He was editor of PC Pro and is co-editor and co-owner of BigTechQuestion.com. He has published a number of articles on TechFinitive covering data, innovation and cybersecurity.