In today’s Whiteboard Wednesday, Justin Pagano, Security Engineer at Rapid7, will discuss the VENOM vulnerability. VENOM is a vulnerability that takes place within the virtual floppy drive code of a virtual machine. If properly exploited, attackers can laterally move from the affected VM and have access to the host, putting your critical assets in jeopardy
Hi. My name's Justin Pagano. I'm a security engineer here at Rapid7. For today's Whiteboard Wednesday we're going to go over the recently disclosed VENOM vulnerability. VENOM stands for virtualized environment neglected operations manipulation. This vulnerability is present in the virtual floppy disk controller or FDC code that's present in a hypervisor package called QEMU. This FDC code is also used in other hypervisor packages such as Xen and KVM.
Show more Show lessExperience the value InsightVM can offer your unique environment with a 30-day free trial.
Get Started