Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTaskDumpTree may lead to out-of-bounds read or it could cause DoS due to integer-overflor (IntPeGetDirectory), TOCTOU (IntPeParseUnwindData) or insufficient validations.
References
Link | Resource |
---|---|
https://www.bitdefender.com/support/security-advisories/lack-validation-data-read-guest-memory-bitdefender-hvi-va-9333/ | Patch Vendor Advisory |
Configurations
Information
Published : 2020-12-17 09:15
Updated : 2020-12-22 07:30
NVD link : CVE-2020-15292
Mitre link : CVE-2020-15292
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
bitdefender
- hypervisor_introspection