Virtualization Vulnerabilities - CompTIA Security+ SY0-701 - 2.3 — Transcript
Full transcript
- 0:02with today's cloud-based infrastructures
- 0:04we can build virtual machines at a
- 0:05moment's notice and we can build many
- 0:08virtual machines simultaneously if
- 0:10you've ever managed a laptop computer or
- 0:12a desktop computer you know what the
- 0:15security concerns might be for a device
- 0:17like this but if you're managing a cloud
- 0:19you may have situations where virtual
- 0:21machines are constantly created and torn
- 0:23down during a normal workday this makes
- 0:26it more challenging to manage the
- 0:27security posture of these virtual
- 0:30devices consider also that these virtual
- 0:32machines may all be built with different
- 0:35configurations these virtual machines
- 0:37might all have a different number of
- 0:38CPUs operational and those CPUs may have
- 0:41different capabilities they might have a
- 0:43different amount of memory or different
- 0:45amount of storage and each one of these
- 0:47systems may be slightly different in how
- 0:49it operates and of course these virtual
- 0:51machines do have aspects of the VMS that
- 0:54are very similar to os's you may be
- 0:56running with other physical devices so
- 0:59the VM M does run a version of an
- 1:01operating system such as Windows or
- 1:03Linux and you should be applying the
- 1:05same type of security best practices to
- 1:07your virtual machine as you have to your
- 1:09physical devices but there are some
- 1:12security vulnerabilities that are
- 1:13specific to the virtual world
- 1:15vulnerabilities such as a local
- 1:17privilege escalation command injection
- 1:19information disclosure and others can
- 1:22still be found in these virtual
- 1:24environments if you've ever used a VM
- 1:27you know that that VM is its own
- 1:29self-contained system with its own CPU
- 1:32memory storage and other resources and
- 1:34it's not possible to somehow move from
- 1:37inside one virtual machine on a
- 1:39hypervisor to things that may be on a
- 1:42different virtual machine on that same
- 1:44hypervisor however there have been
- 1:46instances where researchers have found
- 1:48ways to jump between these VMS this is
- 1:51called a VM escape and it allows the
- 1:53attacker to get access to one virtual
- 1:56machine and then somehow find their way
- 1:58to connect to other virtual machines on
- 2:01that same hypervisor some hypervisors
- 2:04may manage tens or even hundreds of
- 2:06different virtual machines which means
- 2:08if you can escape from one VM and move
- 2:11to another VM on that same hypervisor
- 2:13you would have a great deal of data that
- 2:15you would be able to access this would
- 2:18obviously be an enormous exploit that
- 2:20would allow an attacker to gain access
- 2:22to many systems simultaneously and all
- 2:25of the data contained within those
- 2:27systems a practical example of a VM
- 2:30Escape occurred in March 20177 at the
- 2:33pwn to own competition this is a hacking
- 2:35contest where if you can pone the device
- 2:38then you would be able to physically own
- 2:40it you get to take that laptop or that
- 2:42computer with you at the end of the
- 2:44contest in this competition attackers
- 2:46were able to use a bug in the JavaScript
- 2:48engine of Microsoft Edge to gain access
- 2:51to a Sandbox that's built into the edge
- 2:54browser from that sandbox they were then
- 2:56able to exploit a vulnerability within
- 2:58the Windows 10 in kernel this allowed
- 3:01them to gain full access to that guest
- 3:03operating system from there they were
- 3:05able to take advantage of a hardware
- 3:07simulation bug within VMware and hop
- 3:10from one VM to another VM within that
- 3:13same hypervisor fortunately this
- 3:16vulnerability was only demonstrated for
- 3:18the first time during this competition
- 3:20which allowed VMware to have some time
- 3:22to create a patch roll out that patch
- 3:24and make sure that no one else could
- 3:25take advantage of this VM Escape another
- 3:29security concern concern for virtual
- 3:30machines is a resource reuse let's
- 3:33consider what a hypervisor is doing for
- 3:35all of the virtual machines connected to
- 3:37a particular piece of Hardware a
- 3:39hypervisor is managing this relationship
- 3:41between the physical world and the
- 3:43virtual world so the hypervisor is
- 3:45allocating a certain amount of memory to
- 3:471 VM a certain amount of storage and a
- 3:49certain amount of network and CPU access
- 3:52although the hypervisor is allocating
- 3:54this amount of resource use for a VM
- 3:57doesn't mean that that VM has exclusive
- 4:00access to that particular resource for
- 4:02example a hypervisor host may have a
- 4:04total of four physical gigabyt of RAM on
- 4:07that particular device but that
- 4:08hypervisor is managing three separate
- 4:11virtual machines and each of the VMS is
- 4:13allocated 2 gbt of ram each obviously
- 4:17the VMS are allocated 6 gabt and we only
- 4:20have four physical gigabytes available
- 4:22for the hypervisor we're relying on that
- 4:24hypervisor to only allocate memory where
- 4:27it's needed which would allow us to use
- 4:29effect ively 6 gig of storage space on a
- 4:32machine that is only equipped with 4 GB
- 4:35this means at certain times that there
- 4:36may be certain memory areas that are
- 4:38shared between different virtual
- 4:40machines and it's the sharing of
- 4:42information where we could run into a
- 4:44problem if the hypervisor has a bug that
- 4:46doesn't properly allow for the sharing
- 4:48of resources it is possible that one VM
- 4:51could write to a memory area and that
- 4:53memory area could be read by a different
- 4:55VM normally the hypervisor would be the
- 4:58component restricted that sharing of
- 5:00information between VMS in this example
- 5:03we can see that the hypervisor does have
- 5:05some type of memory management issue
- 5:07once that code is updated that
- 5:09particular sharing would no longer take
- 5:10place and we can avoid any type of
- 5:12resource
- 5:23reuse
About this transcript
This page contains the full transcript of Virtualization Vulnerabilities - CompTIA Security+ SY0-701 - 2.3 by Professor Messer, generated from the public captions YouTube serves with the video. The transcript has 912 words across 138 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.