CVE-2022-35867 is a local privilege escalation vulnerability affecting xhyve, specifically within the e1000 virtual device. It stems from improper validation of user-supplied data length, leading to a stack-based buffer overflow. An attacker with high-privileged code execution on a guest system can exploit this to gain arbitrary code execution within the hypervisor's context. Rated Medium (CVSS 6.7), this vulnerability requires high privileges and local access, but can lead to complete compromise of confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.2.0CPE matchmatch criteria | cpe:2.3:a:xhyve_project:xhyve:0.2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.