Virtual switch

The Hyper-V virtual switch, vmswitch, runs in the host kernel and processes the network frames guests send. Because it parses guest-controlled packet data in the most privileged context, a memory-corruption flaw there is host kernel code execution, reached from any guest that has a virtual network adapter. This makes it the highest-impact Hyper-V escape surface.

text
vmswitch escape surface:
- Guest frame parsing and header handling in the host kernel
- Offload and extension processing

Exploitation notes#

  • It is reachable from any guest with a virtual NIC, with no special configuration, which is what makes it so dangerous.
  • Success lands directly in the host kernel, bypassing the worker-process boundary that bounds synthetic-device bugs.
  • This is a recurring high-severity Hyper-V class in Microsoft's advisories.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more