First published: Thu Dec 17 2020(Updated: )
Compiler Optimization Removal or Modification of Security-critical Code vulnerability in IntPeParseUnwindData() results in multiple dereferences to the same pointer. If the pointer is located in memory-mapped from the guest space, this may cause a race-condition where the generated code would dereference the same address twice, thus obtaining different values, which may lead to arbitrary code execution. This issue affects: Bitdefender Hypervisor Introspection versions prior to 1.132.2.
Credit: cve-requests@bitdefender.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bitdefender Hypervisor Introspection | <1.132.2 |
The issue has been fixed in Introcore 1.132.2.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15294 is a vulnerability that allows for compiler optimization removal or modification of security-critical code in the IntPeParseUnwindData() function, leading to potential race conditions and dereferences to the same pointer.
The Bitdefender Hypervisor Introspection software up to version 1.132.2 is affected by CVE-2020-15294.
CVE-2020-15294 has a severity level of 7 (high).
To fix CVE-2020-15294, users should update their Bitdefender Hypervisor Introspection software to a version beyond 1.132.2.
More information about CVE-2020-15294 can be found at the following link: [bitdefender.com/support/security-advisories/compiler-optimization-removal-modification-security-critical-code-vulnerability-bitdefender-hypervisor-introspection-va-9339](https://www.bitdefender.com/support/security-advisories/compiler-optimization-removal-modification-security-critical-code-vulnerability-bitdefender-hypervisor-introspection-va-9339/)