What is virtual machine escape? - Definition from WhatIs.com

Definition

virtual machine escape

Part of the Security management glossary:

Virtual machine escape is an exploit in which the attacker runs code on a VM that allows an operating system running within it to break out and interact directly with the hypervisor.

Such an exploit could give the attacker access to the host operating system and all other virtual machines (VMs) running on that host. Although there have been no incidents reported in the wild, VM escape is considered to be the most serious threat to virtual machine security.

Virtual machines are designed to run in self-contained, isolated environments in the host. Each VM should be, in effect, a separate system, isolated from the host operating system and any other VMs running on the same machine. The hypervisor is an intermediary between the host operating system and virtual machines. It controls the host processor and allocates resources as required to each guest operating system. 

Here's Ed Skoudis' explanation of the risk:

"If the attacker can compromise the virtual machines, they will likely have control of all of the guests, since the guests are merely subsets of the program itself. Also, most virtual machines run with very high privileges on the host because a virtual machine needs comprehensive access to the host's hardware so it can then map the real hardware into virtualized hardware for the guests. Thus, compromising the virtual machine means not only that the guests are goners, but the host is also likely lost."

To minimize vulnerability to VM escape, Skoudis recommends that you:

  • Keep virtual machine software patched.
  • Install only the resource-sharing features that you really need.
  • Keep software installations to a minimum because each program brings its own vulnerabilities.

This was last updated in April 2016
Posted by: Margaret Rouse

Related Terms

Definitions

  • honeypot (honey pot)

    - A honeypot is a computer system that is set up to act as a decoy to lure cyberattacks and to detect, deflect, or study attempts to gain unauthorized access to information systems. (SearchSecurity.com)

  • Secure Shell (SSH)

    - Secure Shell (SSH) is a network protocol that secures data communications between computers on an insecure network using strong authentication and encryption. SSH also refers to the utility suite t... (SearchSecurity.com)

  • triage

    - Triage is the procedure of assigning levels of priority to tasks or individuals to determine the most effective order in which to deal with them. The first usage of the term in this sense was in th... (WhatIs.com)

Glossaries

  • Security management

    - Terms related to security management, including definitions about intrusion detection systems (IDS) and words and phrases about asset management, security policies, security monitoring, authorizati...

  • Internet applications

    - This WhatIs.com glossary contains terms related to Internet applications, including definitions about Software as a Service (SaaS) delivery models and words and phrases about web sites, e-commerce ...

Ask a Question About virtual machine escapePowered by ITKnowledgeExchange.com

Get answers from your peers on your most technical challenges

Tech TalkComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.