The Hyper-V virtual switch, vmswitch, runs in the host kernel and processes the network frames guests send. Because it parses guest-controlled packet data in the most privileged context, a memory-corruption flaw there is host kernel code execution, reached from any guest that has a virtual network adapter. This makes it the highest-impact Hyper-V escape surface.
vmswitch escape surface:
- Guest frame parsing and header handling in the host kernel
- Offload and extension processing
Exploitation notes#
- It is reachable from any guest with a virtual NIC, with no special configuration, which is what makes it so dangerous.
- Success lands directly in the host kernel, bypassing the worker-process boundary that bounds synthetic-device bugs.
- This is a recurring high-severity Hyper-V class in Microsoft's advisories.