Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain Attacks

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Pan, Gaoning, Tao, Yiming, Wang, Qinying, Wu, Chunming, Hu, Mingde, Ren, Yizhi, Ji, Shouling
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915696052535296
author Pan, Gaoning
Tao, Yiming
Wang, Qinying
Wu, Chunming
Hu, Mingde
Ren, Yizhi
Ji, Shouling
author_facet Pan, Gaoning
Tao, Yiming
Wang, Qinying
Wu, Chunming
Hu, Mingde
Ren, Yizhi
Ji, Shouling
contents Hypervisors are under threat by critical memory safety vulnerabilities, with pointer corruption being one of the most prevalent and severe forms. Existing exploitation frameworks depend on identifying highly-constrained structures in the host machine and accurately determining their runtime addresses, which is ineffective in hypervisor environments where such structures are rare and further obfuscated by Address Space Layout Randomization (ASLR). We instead observe that modern virtualization environments exhibit weak memory isolation -- guest memory is fully attacker-controlled yet accessible from the host, providing a reliable primitive for exploitation. Based on this observation, we present the first systematic characterization and taxonomy of Cross-Domain Attacks (CDA), a class of exploitation techniques that enable capability escalation through guest memory reuse. To automate this process, we develop a system that identifies cross-domain gadgets, matches them with corrupted pointers, synthesizes triggering inputs, and assembles complete exploit chains. Our evaluation on 15 real-world vulnerabilities across QEMU and VirtualBox shows that CDA is widely applicable and effective.
format Preprint
id arxiv_https___arxiv_org_abs_2512_04260
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain Attacks
Pan, Gaoning
Tao, Yiming
Wang, Qinying
Wu, Chunming
Hu, Mingde
Ren, Yizhi
Ji, Shouling
Cryptography and Security
Hypervisors are under threat by critical memory safety vulnerabilities, with pointer corruption being one of the most prevalent and severe forms. Existing exploitation frameworks depend on identifying highly-constrained structures in the host machine and accurately determining their runtime addresses, which is ineffective in hypervisor environments where such structures are rare and further obfuscated by Address Space Layout Randomization (ASLR). We instead observe that modern virtualization environments exhibit weak memory isolation -- guest memory is fully attacker-controlled yet accessible from the host, providing a reliable primitive for exploitation. Based on this observation, we present the first systematic characterization and taxonomy of Cross-Domain Attacks (CDA), a class of exploitation techniques that enable capability escalation through guest memory reuse. To automate this process, we develop a system that identifies cross-domain gadgets, matches them with corrupted pointers, synthesizes triggering inputs, and assembles complete exploit chains. Our evaluation on 15 real-world vulnerabilities across QEMU and VirtualBox shows that CDA is widely applicable and effective.
title Breaking Isolation: A New Perspective on Hypervisor Exploitation via Cross-Domain Attacks
topic Cryptography and Security
url https://arxiv.org/abs/2512.04260