Guest to host escape

AHV runs its guests on QEMU and KVM, so escaping an AHV VM is a QEMU device-model escape, identical in surface and technique to any KVM host. Code execution lands in the QEMU process on the AHV host. From the host, the local Controller VM and the storage fabric it serves are reachable, which is the path from one VM to cluster-wide impact.

text
Nutanix AHV guest escape surface:
- The QEMU device models (virtio, NICs, USB, SCSI) -> see KVM/QEMU
- From the AHV host: the local CVM and the storage fabric

Exploitation notes#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more