Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15294

Опубликовано: 17 дек. 2020
Источник: nvd
CVSS3: 7.8
CVSS3: 7
CVSS2: 4.4
EPSS Низкий

Описание

Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results in multiple dereferences to the same pointer. If the pointer is located in memory-mapped from the guest space, this may cause a race-condition where the generated code would dereference the same address twice, thus obtaining different values, which may lead to arbitrary code execution. This issue affects: Bitdefender Hypervisor Introspection versions prior to 1.132.2.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bitdefender:hypervisor_introspection:*:*:*:*:*:*:*:*
Версия до 1.132.2 (исключая)

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

7 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-733
NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results in multiple dereferences to the same pointer. If the pointer is located in memory-mapped from the guest space, this may cause a race-condition where the generated code would dereference the same address twice, thus obtaining different values, which may lead to arbitrary code execution. This issue affects: Bitdefender Hypervisor Introspection versions prior to 1.132.2.

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

7 High

CVSS3

4.4 Medium

CVSS2

Дефекты

CWE-733
NVD-CWE-Other