Impact
The vulnerability exists in the virtio-win viosock.sys driver used in Windows paravirtualized guests for QEMU and KVM. From release mm210 until mm320, a local low‑privilege process can submit an IOCTL_SELECT request with attacker‑controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32‑bit sum used by VIOSockSelect for bounds checking. The summed value can pass the FD_SETSIZE check even though an individual descriptor count is much larger than expected, allowing VIOSockSelectCopyFds to iterate using the unchecked count and write beyond the allocated pPkt->Fds array in the NonPagedPool kernel heap. This heap overflow can corrupt kernel memory and enable privilege escalation in the Windows guest.
Affected Systems
The vulnerability affects Windows systems that load the virtio-win viosock.sys driver. It applies to device versions from mm210 up to, but not including, mm320, the release that contains the fix. Any virtual machine using these earlier virtio-win driver releases therefore runs at risk.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact vulnerability. The EPSS score is not available, and the flaw is not currently listed in the CISA KEV catalog, suggesting moderate but not high exploitation probability at present. Exploitation requires a low‑integrity process to issue the crafted IOCTL, so the attack vector is local. If leveraged successfully, the integer overflow could be used to overwrite kernel memory and execute arbitrary code, resulting in complete privilege escalation.
OpenCVE Enrichment