PSIRT Advisory

CVE-2015-3456 "VENOM" vulnerability

Description

The VENOM (Virtualized Environment Neglected Operations Manipulation) vulnerability impacts popular virtualization platforms, including QEMU, Xen, KVM, and Oracle's VirtualBox.
It consists in a buffer overflow condition in the FDC (Floppy Disk Controller) emulation code.
Fortinet virtual appliances including FortiOS, FortiManager, FortiAnalyzer and any other product running on Hyper-V, Xen and KVM are not affected.

Impact

Guest VM DoS and VM escape

Affected Products

FortiSandbox 2.0.2 and below is theoretically affected, however no working exploit code has been known to be available so far.

Solutions

Upgrade to FortiSandbox 2.0.3.