AHV runs its guests on QEMU and KVM, so escaping an AHV VM is a QEMU device-model escape, identical in surface and technique to any KVM host. Code execution lands in the QEMU process on the AHV host. From the host, the local Controller VM and the storage fabric it serves are reachable, which is the path from one VM to cluster-wide impact.
Nutanix AHV guest escape surface:
- The QEMU device models (virtio, NICs, USB, SCSI) -> see KVM/QEMU
- From the AHV host: the local CVM and the storage fabric
Exploitation notes#
- The technique and surface are the KVM and QEMU guest to host escape, bounded by the AHV host's QEMU confinement.
- The escape's value is the pivot: AHV host to CVM to the distributed storage, which holds every VM's disks for Disk and snapshot theft.
- Nutanix-specific and QEMU named issues are under Known escape exploits.