Xen SMEP & SMAP Bypass Technique Analysis
ID: 11190848-9f02-5a85-abfe-f9ba3bed7638
STIX ID: report--11190848-9f02-5a85-abfe-f9ba3bed7638
Feed Name: NCC Research
This 2015 technical blog explains how Xen's direct-mapped memory and the guest-exposed physical-to-machine (p2m) mapping can be abused to bypass SMEP and SMAP by computing DIRECTMAP_VIRT_START + MFN to obtain a ring0-only RWX virtual address that points to guest-controlled data, enabling hypervisor-level code execution from a compromised guest; the author demonstrates the technique, provides example code, discusses payload staging and data tunnelling, and suggests mitigations such as making the direct map non-executable or randomising hypervisor memory layout.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
