CVE-2020-15292: Lack of validation on data read from guest memory in Bitdefender HVI (VA-9333)
Lack of validation on data read from guest memory in IntPeGetDirectory, IntPeParseUnwindData, IntLogExceptionRecord, IntKsymExpandSymbol and IntLixTaskDumpTree may lead to out-of-bounds read or it could cause DoS due to integer-overflor (IntPeGetDirectory), TOCTOU (IntPeParseUnwindData) or insufficient validations.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2020-15292?
CVE-2020-15292 is a vulnerability that allows for lack of validation on data read from guest memory in Bitdefender Hypervisor Introspection.
What is the severity of CVE-2020-15292?
The severity of CVE-2020-15292 is medium (5.5).
Which software is affected by CVE-2020-15292?
Bitdefender Hypervisor Introspection up to version 1.132.2 is affected by CVE-2020-15292.
How can this vulnerability be exploited?
This vulnerability can be exploited by reading data from guest memory without proper validation, leading to out-of-bounds reads or denial of service attacks.
Is there a fix available for CVE-2020-15292?
Yes, Bitdefender has released a fix for this vulnerability. It is recommended to update to version 1.132.2 or later of Bitdefender Hypervisor Introspection.